<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Identity 2.5]]></title><description><![CDATA[Are you interested in the future of Identity?  This newsletter examines the very fundamental of Identity, analyses our options, and suggests possible futures.]]></description><link>https://www.newsletters.identity25.com</link><image><url>https://substackcdn.com/image/fetch/$s_!QRGk!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa560a9d9-39ef-44fd-8089-c53748a41ff0_600x600.png</url><title>Identity 2.5</title><link>https://www.newsletters.identity25.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 02 May 2026 12:31:15 GMT</lastBuildDate><atom:link href="https://www.newsletters.identity25.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Dr Alan Mayo]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[identity2.5@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[identity2.5@substack.com]]></itunes:email><itunes:name><![CDATA[Dr Alan Mayo]]></itunes:name></itunes:owner><itunes:author><![CDATA[Dr Alan Mayo]]></itunes:author><googleplay:owner><![CDATA[identity2.5@substack.com]]></googleplay:owner><googleplay:email><![CDATA[identity2.5@substack.com]]></googleplay:email><googleplay:author><![CDATA[Dr Alan Mayo]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The State of Identity Planetwise]]></title><description><![CDATA[I've been trying to write this since before Christmas and recent events have finally clarified a few things for me...]]></description><link>https://www.newsletters.identity25.com/p/the-state-of-identity-planetwise</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/the-state-of-identity-planetwise</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sun, 05 Apr 2026 03:21:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KKrg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KKrg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KKrg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KKrg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2693127,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/193224895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KKrg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KKrg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe306d175-72ac-4d45-85de-627d7c92e888_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We have evolved to three identity models. A colleague of mine in a complex IT project, along time ago, stated &#8220;We have three options, one of them must be right&#8221;. Fortunately he was right &#8211; I hope the same holds for Identity.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The Problem</h2><p>Let&#8217;s just remind ourselves that Identity is a problem due to poor solutions and a lack of solutions:</p><ol><li><p> <strong>Accessing online services </strong>is a painful<strong> </strong>Multi-Factor Authentication (MFA) hell.</p></li><li><p> <strong>Account opening</strong> requires the use of complex and time-consuming Identity Verification solutions (i.e. Anti-Money Laundering, Countering the Financing of Terrorism solutions).</p></li><li><p> <strong>Simple legal approval processes</strong> (e.g. approve a bank signatory for a charitable trust) face the same requirements.</p></li><li><p> <strong>Fraudulent scams </strong>exist as there are limited ways to authenticate an organization.</p></li><li><p> <strong>A lack of age assurance </strong>causes social harm<strong> (</strong>social media, alcohol sales, adult content, and gambling).</p></li></ol><p>And Reusable Digital Identity (RDI) could solve them all. While we have Digital Identity (all those servers with all that data on you), we struggle to re-use it and often we fall back on physical documents. So what are we doing about it?</p><h2>Three National RDI Models</h2><p>As the great Identity evolution rolls on, there are three promoted national RDI models:</p><ol><li><p>Networked Identity</p></li><li><p>Decentralized Identity</p></li><li><p>Credential Identity</p></li></ol><h3>Networked Identity</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!02EO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!02EO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!02EO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!02EO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!02EO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!02EO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2787322,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/193224895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!02EO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!02EO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!02EO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!02EO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faeab75a7-a04c-43e4-83cc-b1f3cbbd73ce_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this model, identity data is held in central registries and is made available through networks.</p><p>Networked Identity is operational to varying degrees for 50% of the planet&#8217;s population. The major players are in Asia with Aadhaar in India and the Chinese solution. Other high-profile solutions exist in Scandinavia and Estonia.</p><p>This model has emerged in countries with strong personal national identity number structures because Networked Identity is just easier if everyone has a number. But, that does not mean Networked Identity is impossible in countries without personal national identity numbers (my approach, General Identity Protocol, solves that problem).</p><p>Note that governments all over the world provide access to government services through a networked model, but they do not necessarily extend this to be an RDI which is more a quantum leap over simply offering your own services online.</p><p>Networked Identity, by volume the most successful model, is evolving incrementally. India is a useful example &#8211; Aadhaar, an amazing accomplishment that registered a population including biometric data, is beginning to develop services based on the established data.</p><p>A common and completely erroneous criticism of Networked Identity is the &#8216;conspiracy theory&#8217; that Networked Identity must result in population surveillance and some sort of dystopian society in which all personal freedoms are lost. Yes, China controls its population, data breaches occur, and social media giants misuse information. But India is a wonderful example of a country that effectively guards against such abuses, governments rarely, if ever, lose their population&#8217;s data, and data misuse has been minimized through privacy laws.</p><p>Central registries are a core component of tax systems that finance countries, welfare systems that provide pensions, education systems that record qualifications, and health systems that monitor people&#8217;s well-being over time. These are necessary and useful tools for a functioning society that wishes to avoid anarchy. Lambasting them as the cause of all societal problems is just silly.</p><p>Networked Identity is established and working &#8211; the questions are how far can it go functionally and will it extend to other jurisdictions?</p><h3>Decentralized Identity</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iVJv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iVJv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iVJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2755395,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/193224895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iVJv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!iVJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3914d08e-f550-4f56-a49c-602a6fe5bdaa_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Decentralized Identity is both an ideological movement and a technology model. Ideologically, Decentralized Identity means putting power into the hands of the individual rather than relying on the state or commercial entities. This is the Self-Sovereign Identity (SSI) approach in which every individual, presumably, is their own sovereign. While the name itself begs the question &#8216;who wants to be the sovereign in a land of a single individual?&#8217;, the movement has attracted support for 20 years at least. The Internet Identity Workshop formed in 2005 is a leading player, as is W3C, and the Sovrin Foundation.</p><p>The movement had a lot of impetus at the time when blockchain solutions were emerging, and utilizes cryptography to support the decentralized model. Initially DIDs, or Decentralized IDs, were the answer but were overtaken somewhat by Credential Identity (see below).</p><p>Now Decentralized Identity seems to be having a sort of revival. The State of Utah has legislated State-Endorsed Digital Identity described in this overview from 17 October 2025:</p><blockquote><p>&#8220;This reflects the founding idea of the United States, that all just powers of government derive from the consent of the governed. SEDI recognizes it is the role of the state to act as a trusted endorser, verifying an individual&#8217;s asserted identity and then issuing an endorsed credential mathematically bound to a digital identifier that the individual alone controls.&#8221;</p></blockquote><p>That is, government powers derive from the consent of the people, so the state should cryptographically sign an individual&#8217;s identity data. The leap from the basis of government to a technical solution is quite something, but is not uncommon in Decentralized Identity.</p><p>Whether SEDI is truly decentralized will become apparent in the future, but it certainly looks like quite a different approach from Credential Identity considered below.</p><h3>Credential Identity</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DEcU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DEcU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DEcU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3194956,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/193224895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DEcU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DEcU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1911d20f-3d35-43d1-9ec7-1b46a6de58a2_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I call this movement Credential Identity for brevity as it could be more correctly called Verifiable Credentials / Digital Wallet Identity. The major movement is the EU that embarked on its EU Digital Identity Wallet (EUDIW) project in 2021 with large scale pilots rolling out from 2023 onwards. Now this approach is being followed in many countries, including New Zealand where I live.</p><p>Credential Identity focuses on, well, Credentials. Credentials are both verified and verifiable. That is, some reliable party signs cryptographically and other parties can then verify the signature.</p><p>Even though on hugely different scales, the EU and New Zealand are following similar paths of building the infrastructure to issue credentials and store them in a smartphone wallet in the hope that, in the future, parties will develop solutions to utilize these stored credentials.</p><p>The challenge for Credential Identity are manifold (see my previous newsletter <a href="https://www.newsletters.identity25.com/p/22-seven-challenges-for-decentralized">Seven Challenges for Credential Identity</a>). One of these challenges is how to authenticate a person. I have asked leading proponents of Credential Identity this question, and they either recognize the issue or suggest that it is all being designed. As I have previously written, there is a distinct possibility that authentication will not make it into the solution which will devolve in Distributed Digital Documents (DDD). And DDD is not RDI (I promise).</p><h2>Summary</h2><p>So there it is, after twenty years a big problem and three options!</p><p>Personally, as per my previous newsletter, <a href="https://www.newsletters.identity25.com/p/24-identity-starts-with-people">Identity Starts with People</a>, I think that people want utility, people trust governments, and that therefore we should deliver identity through Networked Identity. It seems the only pragmatic solution given that we have centralized personal digital identity data which we can re-use.</p><p>Instead we pursue a immensely complex and probably unimplementable Credential Identity or an ideological-based Decentralized Identity that is simply a theoretical pipe dream.</p><p>But the tech world wants to play, so the story will go on!</p><p>regards</p><p>Alan</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[24. Identity Starts with People]]></title><description><![CDATA[Maori proverb: "He aha te mea nui o te ao? He t&#257;ngata, he t&#257;ngata, he t&#257;ngata" In English, "What is the most important thing in the world? It is people, it is people, it is people."]]></description><link>https://www.newsletters.identity25.com/p/24-identity-starts-with-people</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/24-identity-starts-with-people</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Wed, 05 Nov 2025 09:59:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SBxC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SBxC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SBxC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SBxC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2377912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SBxC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!SBxC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8552ff12-51c5-4eb8-b8cf-e20541fca6fd_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Identity starts with people. People are what it is all about. People&#8217;s views, wants, and expectations should be the starting point for Identity.</p><p>Too often, people are deliberately misrepresented by ideologically and commercially-driven technology interests for their own gain. This needs to stop.</p><p>Here are my four <em>people propositions</em> based upon:</p><ul><li><p>my <em>understanding</em> of the current identity world and</p></li><li><p>my <em>reasoning</em> for the conclusions I make.</p></li></ul><p>I invite you to invoke your own <em>understanding</em> and <em>reasoning</em> as you read these propositions.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h3>People Trust Government and Organizations</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xl4J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xl4J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xl4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2422767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xl4J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!xl4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec90c99f-365e-4ff7-8d52-3c77254fbdd2_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>So much of Identity development is influenced by the bizarre notion that people do not trust governments and organizations. Of course, people do not always like or agree with these bodies, but the big question is how people perceive of their trustworthiness. And they TRUST them!</p><p>I base my proposition on our current reality. Today, people trust governments to keep track of citizens. Today, people trust banks with their identities and their money. Today, people trust organizations with personal information. Today, people empower organizations to act on their behalf financially.</p><p>Today, that is what people do. We do not see street marches protesting against government managed identity. We do see most people engaging with identity services provided by governments and organizations.</p><p>We do not live in a world of distrust of governments and organizations. People have trusted these bodies for a long time and there is no indication that this is about to change, no matter how many misleading and inflammatory surveys are done.</p><p>Don&#8217;t believe me? Ask yourself.</p><h3>People Expect Governments and Organizations to Maintain Our Identities</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pMBN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pMBN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pMBN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2256133,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pMBN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!pMBN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f1c62ff-9bd1-460e-8ebd-267398cc0b79_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Yes, that&#8217;s right. People do not want to be responsible for maintaining their own Personal Identity Information (PII) &#8211; they EXPECT governments and organizations to do that for them!</p><p>This PII is held centrally in large IT systems and locally as physical documents issued to individuals (passports, drivers licenses, university degrees etc). For an individual, being responsible for the security of these physical documents is neither a rewarding nor edifying experience. The perceived value of the documents means that storing them and carrying them involves some risk we would be better off without.</p><p>So, the idea that we now go to the next step and ask the public to manage the original copies of their PII, the source of truth, is ludicrous.</p><p>We know that is what governments and organizations are there for! That is what they are good at. Ok, I feel the &#8216;but the data breaches&#8217; brigade reaching for the reply key, but such breaches are extremely rare for governments, are not as prevalent as reported for organizations, often involve information that was publicly available, and the situation is improving as one should expect.</p><p>We know PII is important and we expect others to maintain it on our behalf. Is that your experience?</p><h3>People Want Utility</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sIWB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sIWB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sIWB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2330645,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sIWB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sIWB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8a43134-2633-4a20-9fa4-f9948040c859_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s right, UTILITY is what people want &#8211; functionality that is easy to use and achieves its purpose. For example, the &#8216;identity hell&#8217; called Multi-Factor Authentication (MFA) wears people down. It is frustrating. People want a better way. The lack of age assurance is problematic. People do not like what is happening to young people because we lack online age checking. People are scared of being defrauded of their life savings &#8211; they want a solution that authenticates those claiming to represent organizations.</p><p>These are all examples of utility and are what I want, and I expect that others do as well. It seems relatively straightforward, but the accepted view of what people want is skewed by biased surveys. Asking an individual if the security of their identity information is important will elicit a positive answer. Ask them if they want to be in control, and they will answer yes. Asking people about the integrity of big business is likely to evoke negative responses. But this doesn&#8217;t mean that people want self-sovereignty. That extrapolation is just dumb (who would really like to be the monarch of a realm of one person?)</p><p>In the end, we just want it to work! Do you?</p><h3>People Will Expect Perfection From Identity Solutions</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IiXW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IiXW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IiXW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2329598,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IiXW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!IiXW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61cd5360-f751-4019-919d-f1d2e51bab75_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It needs to work PERFECTLY, that is 100%. As the world moves to forms of Digital Identity re-use, will 99% be ok?</p><p>Payments and Identity are two very similar processes and the public judges them in a similar manner. How would you feel if payments were correct 99% of the time and 1% of the time you were charged the wrong amount?</p><p>For Identity, think about age assurance. Imagine if your 13-year-old beat the age check for buying alcohol only 5% of the time. It is only about one weekend every six months. Happy with that?</p><p>How about on-line fraud? What if only 0.1% of people looking to invest are fraudulently robbed of their life savings annually? It is probably only 0.1% of the population trying to invest, so in NZ this is only 0.1% of 5,000 or only 5 people per year! Is that acceptable?</p><p>Would you accept 99%?</p><h3>Summary</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hwZR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hwZR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 424w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 848w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 1272w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hwZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png" width="1456" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/178060702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hwZR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 424w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 848w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 1272w, https://substackcdn.com/image/fetch/$s_!hwZR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17253581-a691-4f90-a157-39fe285b4cd9_2068x1041.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Identity is about people, and it should be driven by people:</p><ol><li><p>people trust governments and organizations with their identity</p></li><li><p>people expect governments and organizations to manage their identity</p></li><li><p>people want utility</p></li><li><p>people expect solutions to be 100%</p></li></ol><p>There are no technology imperatives in any of these propositions - technology flows from what people want from Identity.</p><p>What do you think?</p><h3>Addendum - Fallacies</h3><p>To highlight these propositions, here are some fallacies:</p><ol><li><p>people don&#8217;t trust organizations so we must develop other solutions</p></li><li><p>governments are untrustworthy so we must remake the Identity world</p></li><li><p>people want full responsibility over their identity data</p></li><li><p>small steps in Identity will be fine, just make it a little bit better</p></li></ol><p>Are these just some shame justifications to the right-handside in the graphic immediately above?</p><p>What do you think??</p><h3>The Bottom Line</h3><p>Identity development should be based on people and on our current Identity context.</p><p>Do you agree?</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[23. Identity is Centralized]]></title><description><![CDATA[Really - could this be true?]]></description><link>https://www.newsletters.identity25.com/p/23-identity-is-centralized</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/23-identity-is-centralized</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Wed, 24 Sep 2025 04:53:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XAzB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XAzB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XAzB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XAzB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3311018,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/174412365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XAzB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!XAzB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F512d8184-fc43-4fe9-bee1-c84dbdc68b4d_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Whoa &#8211; where did that idea come from?</p><p>Identity discussions revolve around competing designs, especially Centralization vs Decentralization. But it is Centralized and will aways be so!</p><p>Yikes &#8211; is this Identity&#8217;s <em>The Truman Show</em> moment?</p><p>Dang.</p><p>Read on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>Identity is Centralized &#8211; now and forever</h2><p>Yes, you betcha it is.</p><p>By centralized, I mean that an individual&#8217;s Personal Identity Information (PII) is held in central databases by central government departments, local government, corporations, companies, societies, and other organizations. The Identity source of truth is the PII in central databases &#8211; we are given physical copies of that PII to use in the form of passports, birth certificates, drivers&#8217; licences and the like.</p><p>And I clearly do NOT mean that there is one big brother database. Don&#8217;t throw that one at me.</p><p>I mean the customer databases that we have today, now, currently everywhere.</p><p>This is fairly mundane so far, nothing controversial here, but wait for it&#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hZwf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hZwf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hZwf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3993087,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/174412365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hZwf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!hZwf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6a5887-1f74-4453-9b6c-a092b2710781_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Identity will remain centralized &#8211; no radical change</h3><p>Really and truly. No kidding here, serious stuff. Why? Because:</p><ul><li><p>People trust organizations with their PII (don&#8217;t get off your horse yet - I&#8217;ll cover this sacred cow in my next newsletter).</p></li><li><p>Organizations need PII to operate.</p></li><li><p>People expect organizations to use their PII effectively to provide services.</p></li><li><p>And the big secret here is that organizations do that job quite well.</p></li><li><p>People expect organizations to respect their privacy and abide by privacy laws and, as we all know, they mostly try to and mostly do.</p></li><li><p>Protecting PII is getting better, and organisations holding high-level assurance PII data are very good at it (e.g. central</p></li></ul><p>Sure, we have short-term operational problems (i.e. 10 years of increasing friction over 50 years of Digital Identity) but <strong>the fundamental design of Centralized Identity is working</strong>, it&#8217;s been here for a long time, and it&#8217;s not going to change.</p><p>I don&#8217;t care how much the anti-establishment ideologues tell me that the mythical centrists are fundamentally flawed bad people, I don&#8217;t believe the techno boffins have a wonderful solution that will make decades of worldwide infrastructure irrelevant, I don&#8217;t think that the blockchain will revolutionize Identity, hackathons will not be drivers of long-term Identity development, and ideology will not triumph over the currently installed Identity base and economics.</p><p>We have Centralized Identity and we will continue to use it as a basic building block of our society.  Decentralized Identity will not replace Centralized Identity</p><p>The question is how to extend and utilise current infrastructure to provide effective Centralized Identity re-use.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kC-n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kC-n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kC-n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3511865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/174412365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kC-n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!kC-n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7b58005-ec65-4215-a561-b605cfc72997_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>So the question is centralized digital identity reuse</h3><p>And this means, of course, how to get a piece of PII from one centralized data source to another (i.e. Identity Provider to Relying Party).</p><p>Do you know what I mean? The question is NOT how to build a new Identity system! The question is how to build a structures that allow current Identity databases to be reused by sharing data.</p><p>And we know that is not easy as we are still relying on physical documents. I&#8217;ve written a lot on this, but now I frame the question differently as <strong>&#8216;finding the best way to enable the re-use of Centralized Digital Identity&#8217;.</strong></p><p>See the difference? This is not a question of building something completely standalone and new. <strong>It is how to extend what we have.</strong></p><h2>And there is an easy way and there is a hard way</h2><ol><li><p>Networked Identity &#8211; extend current networking technologies to cater for the complexities of Identity and base this on lessons from operating solutions in Estonia and Scandinavia.</p></li><li><p>Decentralized Identity &#8211; create billions of PII copies housed in apps on countless varieties of personal digital devices, that are fully secure, supported by multiple asynchronous processes and evolving crypto-based technologies, with additional techniques to ensure credentials are up-to-date, and with subsystems to verify organizations etc.</p></li></ol><p>Think about the size and complexity.</p><p><strong>How much should you need to build to move some PII from here to there!</strong></p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[22. Seven Challenges for Credential Identity]]></title><description><![CDATA[Credential Identity is an alternative to Networked Identity. But to work, there are seven challenges that must be met.]]></description><link>https://www.newsletters.identity25.com/p/22-seven-challenges-for-decentralized</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/22-seven-challenges-for-decentralized</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sat, 20 Sep 2025 20:33:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jG3_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jG3_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jG3_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jG3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2151520,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/174119696?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jG3_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!jG3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd30f47c0-dd21-48a9-a12b-07e001169627_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>An Admission</h2><p>I originally wrote this newsletter about what I termed, at the time, Decentralized Identity.  Developments since September 2025 show we have three different architectural models and this newsletter better pertains Credential Identity hence the revision.  See my later newsletter for an in-depth discussion of the three models.</p><h2>Credential Identity</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Teo2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Teo2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 424w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 848w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Teo2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png" width="1456" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1702036,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/174119696?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Teo2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 424w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 848w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!Teo2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F644ea792-a4bf-4716-9087-823c9784a4fb_1980x1055.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Credential Identity is what the EU is promoting through the EU Digital Identity Wallet project.  Others will call this the Verifiable Credentials / Digital Wallet Identity model or similar.  </p><p>For brevity and as the central component of the model is the Verifiable Credential, I call this movement Credential Identity.</p><h2>Challenge 1: A Verified Identity</h2><p>Centralized systems sit on national infrastructures, good quality identity profiles, and long-standing processes. <strong>Credential Identity has no verified people so they must be imported.  </strong>You could run Identity Verification  (e.g. KYC/AML), but the question remains: was it good enough?  Or, you could import profiles from a centralized system.  And will wallets all behave differently.  </p><p>For Credential Identity to flourish, it will need to <strong>determine where identities originate from and will need to enforce common standards</strong> across all wallet providers.</p><h2>Challenge 2: A Secure Platform</h2><p>Identity <strong>wallets will be targets.</strong> A smartphone is a personal digital device. It is not like a government server with firewalls and teams of security experts to protect it. A smartphone in the hands of the bad guys is all alone and vulnerable.</p><p>People I have talked to, who are working closely on the issue in Europe, do not rule out a hardware solution: 5,000,000 hardware devices for New Zealand, please! Obviously this is unlikely, but Credential needs to describe <strong>how a secure platform can be implemented</strong> (we are waiting!).</p><h2>Challenge 3: Ability to Authenticate</h2><p>Let&#8217;s assume that we have the person embedded safely in a smartphone.  We need to authenticate them before letting them receive and distribute their credentials.  Centralization is not a model solution here either&#8212;primarily because it&#8217;s not easy.</p><p>But authentication is still inherently challenging and Credential Identity needs to converge on a <strong>consistent and secure authentication approach</strong>.  Surely we cannot put up with Multi-Factor Authentication hell?</p><h2>Challenge 4: Ability to Load Credentials</h2><p>Just a bit of data transfer? Not quite. Whenever Personally Identifiable Information (PII) is augmented, there should be a check that the new PII is <strong>for the same identity</strong>. That is what we expect centralized systems to do, and clearly Credential Identity will need a method for doing so.</p><p>Given that the credential is likely to be a verifiable credential, which field(s) will be used to match against the identity stored on the smartphone? This may have been settled in some designs, but we have yet to see a complete design; hence I keep asking these questions.</p><p>Note also that if there is one credential that identifies a person, will that become a default national identifier?</p><h2>Challenge 5: Distributing Credentials to Relying Parties</h2><p>Who are they, these relying parties? For Credential Identity, those other relying parties may appear as an app on a smartphone&#8212;how can the app, and thus the organization, be authenticated? Currently <strong>we lack the ability to verify organizations</strong> and so Credential Identity will need to be the first to solve the problem. Credential Identity aims to avoid &#8216;big brother&#8217; solutions, so a central register should be out of scope? So how will they do it? And then, of course, a method is required to exchange credentials but that should be something can be resolved with the use of good standards.</p><h2>Challenge 6: Keeping it Up-To-Date</h2><p>The best use case to think about is drivers&#8217; licenses. If we put a copy in a Digital Wallet, <strong>how do we know it is up-to-date?</strong> If a license is revoked, clearly this must be reflected when the credential is shared. I remember the bad old days in banking with &#8216;hot card files&#8217; and similar technologies. It was purgatory!</p><p>Of course, there is always the possibility of online checks but if a many-to-many network is to be envisaged, there will be issues of contention etc. When suddenly everyone relies on everyone, there is significant risk that we all look rather embarrassed. Maybe implement a switched network, but isn&#8217;t that what Credential Identity wants to avoid?</p><h2>Challenge 7: Recovery</h2><p>Smartphones are lost regularly - <strong>a recovery process is essential.</strong> The more credentials that Decentralized supports, the harder recovery will become. Think of rebuilding a wallet with credentials from 5-10 sources! Perhaps we could have a central recovery service, but again isn&#8217;t that exactly what Credential Identity aims to avoid?</p><h2>Summary</h2><p>Credential Identity aims to replicate or replace centralized identity.</p><p>But Credential Identity is <strong>a complex solution with many moving parts</strong>.  This complexity and numeracy creates many challenges.</p><p>To commit to Credential Identity, <strong>we need to see a plan </strong>to solve the seven challenges above (and probably a few more as well). Such a plan must include functional design, systems topography, systems architecture, and development feasibility.</p><p>Without a plan, we risk everything.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[21. The Plummet]]></title><description><![CDATA[How did that happen? We were promised a reusable Digital Identity ecosystem, and now we are getting digital copies of documents on a smartphone?]]></description><link>https://www.newsletters.identity25.com/p/21-the-plummet</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/21-the-plummet</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 31 Jul 2025 19:00:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!azsY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!azsY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!azsY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!azsY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!azsY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!azsY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!azsY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2190072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/169774206?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!azsY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!azsY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!azsY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!azsY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd62846f9-bba7-488a-9623-74b5e60e164e_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With New Zealand&#8217;s premier identity conference, 2025 Digital Trust Hui Taumata, happening within 2 weeks, I thought it would be useful to report the plummet of Decentralized Identity down to Distributed Digital Documents. To put this plummet into perspective, I have written a report card for Identity for the last 50 years. Identity only gets a C-, and my analysis that follows describes this major contraction reusable Identity to digital documents.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>Lifetime Achievements: C-</h2><p>In the last 50 years Identity achievements are:</p><ol><li><p>Paper-based identity records have been replaced with centralized digital identity databases.</p></li><li><p>Physical identity documents are created from these databases for in-person identity.</p></li><li><p>On-line identity started on the Internet with username/password and evolved to Multi-Factor Authentication (MFA).</p></li><li><p>Federated Identity emerged a) to support integrated online government services, b) in the corporate arena as the Identity and Access Management (IAM) industry, and c) as a method of leveraging the large identity databases maintained by social media and big tech</p></li><li><p>Identity Verification, based on physical identity documents, was developed by the Know Your Customer (KYC) industry, a response to Anti-Money Laundering / Countering the Financing of Terrorism legislation (AML/CFT).</p></li></ol><p>What has not been achieved is:</p><ol><li><p>Secure in-person Identity (e.g. a secure Covid passport)</p></li><li><p> Secure and easy to use on-line Identity</p></li><li><p>On-telephone Identity</p></li><li><p>Low-cost solutions</p></li><li><p> Age Assurance to protect youth from social media, adult content, gambling, and alcohol sales</p></li><li><p>On-line authentication to protect individual from fraudulent financial scams.</p></li></ol><p>Identity development has been haphazard in the last 50 years &#8211; it has lacked an overall design and any consolidated direction. We still use physical documents. On-line Identity is a mess. The social harm due to a lack of Age Assurance is not imaginary &#8211; it is happening right now, and solutions are limited. Simply put, we lack the reusable digital identity that everyone desires (except the incumbent KYC industry which would be marginalized if there was reusable digital identity).</p><p>The outliers to all this are the national Identity solutions of Scandinavia and Estonia. With the advantage of compulsory personal numbers, these countries have developed common second factors of authentication (2FA) solutions and the sharing of basic government data. While not reusable identity, these solutions are highly effective and meet many of the identity needs of their societies.</p><p>But overall, Identity&#8217;s grade is C- at best. So, what is Identity doing to solve it?</p><h2>Current Activities</h2><p>Simplifying in the extreme, I see the major courses being pursued now as Decentralization, Distributed Digital Documents (DDD), Probabilistic Models, and Legislation.</p><h4>Decentralization</h4><p>I have written many newsletters on the challenges for Decentralization: securing data on personal digital devices, establishing initial verified identities on these same devices, exchanging credentials in multiple environments, recovery processes for lost devices etc. These many challenges are probably why, 20 years after the Internet Identity workshop started promoting Decentralization, there is no implementation of decentralized reusable Identity. We have had a series of technologies including DIDs, Digital Wallets, and Verifiable Credentials but no decentralized ecosystem design. We have technologies, but no functional solution. Decentralization has not delivered reusable Digital Identity.</p><h4>Distributed Digital Documents (DDD)</h4><p>What is coming to fruition is Distributed Digital Documents, this being Verifiable Credentials stored in Digital Wallets. Essentially this replicates physical identity documents in physical wallets but with better verifiability of the documents. MATTR&#8217;s recent announcement, that it had been selected to provide a credential SDK for the New Zealand&#8217;s government&#8217;s app, highlights the utility of this solution: &#8220;It marks a major step toward Kiwis being able to carry trusted digital versions of their credentials (like driver&#8217;s licences) in their own digital wallets&#8221;.</p><p>But note that there is no mention of reusable Digital Identity. Because Decentralization is so complex we have descended to a lesser deliverable &#8211; DDD (maybe we can call this triple D). And note that the descent is huge, from an ecosystem to a digital copy, hence the use of the word &#8216;plummet&#8217;.</p><h4>Probabilistic Models</h4><p>Due to both the need for Age Assurance and the weaknesses in current Identity solutions, Age Estimation and Age Inference have emerged. Both are based on probability &#8211; that people who look and move like this are normally a certain age and people who have a certain digital footprint are normally a certain age. But, of course, they have inherent error rates, and you do not know when an error occurs. While these techniques may have applicability for statistical analysis of behaviour, they are unlikely to be the answer for high assurance Identity.</p><h4>Legislation</h4><p>We have legislation that:</p><ol><li><p> proscribes KYC processes creating Identity Verification</p></li><li><p>establishes national trust frameworks but without any tangible results</p></li><li><p>establishes customer data rights but without any delivery to date</p></li><li><p>proscribes an EU Digital Identity Wallet that has given rise to a pilot industry</p></li><li><p>regulates age assurance resulting in rushed low-quality solutions (e.g. UK) or the shutting down of services (e.g. adult entertainment in some US states).</p></li></ol><p>Legislation is clearly important to a society, but it has yet to deliver a Digital Identity ecosystem and is unlikely to do so. Why not? Because it is there to <em>regulate</em> what society produces, not to <em>dictate </em>what society produces.</p><h2>The Plummet</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r79e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r79e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 424w, https://substackcdn.com/image/fetch/$s_!r79e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 848w, https://substackcdn.com/image/fetch/$s_!r79e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 1272w, https://substackcdn.com/image/fetch/$s_!r79e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r79e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png" width="214" height="265" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:265,&quot;width&quot;:214,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/169774206?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!r79e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 424w, https://substackcdn.com/image/fetch/$s_!r79e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 848w, https://substackcdn.com/image/fetch/$s_!r79e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 1272w, https://substackcdn.com/image/fetch/$s_!r79e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fab434c-ce43-4f85-8733-dc5479b34760_214x265.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>50 years of below-average performance has left us with physical identity documents, on-line federated identity, and an incumbent KYC industry. We have no reuseable Digital Identity ecosystem.</p><p>In the last 10 years, Identity has disappeared down a series of ideological and technology rabbit holes. Decentralization, driven by an ideological distrust of central control and fuelled by a cryptographic industry, has failed to deliver and has plummeted to Distributed Digital Documents.</p><p>Side bets, probabilistic identity and legislating solutions into existence, have not and will not work.</p><p>After 50 years, we can now put a digital version of an Identity Document onto a smartphone. That&#8217;s right&#8212; what we digitized 50 years ago can now be put on a smartphone. Gee whiz.</p><p>The dream of a Digital Identity ecosystem is yet to be realized.</p><p>Alan Mayo</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[20. Age Assurance – Decision Time!]]></title><description><![CDATA[Age Assurance is upon us - decisions will and must be made. We are woefully prepared, but we still have an opportunity to get it right if we 1) recognize the situation and 2) ask the right questions.]]></description><link>https://www.newsletters.identity25.com/p/20-age-assurance-decision-time</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/20-age-assurance-decision-time</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Tue, 15 Jul 2025 02:43:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qFD5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qFD5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qFD5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qFD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2714202,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/168354210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qFD5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!qFD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68660103-2b5f-4d18-a16d-07590df1d736_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Age Assurance is the big Digital Identity issue right now. The Australian Government has legislated that <a href="https://www.minterellison.co.nz/insights/australian-government-bans-social-media-for-those">Age Assurance for social media</a> must be in place by December 2025 and are running an <a href="https://ageassurance.com.au/">Age Assurance Technology Trial</a>. In New Zealand <a href="https://www.rnz.co.nz/news/political/560074/national-mp-puts-forward-member-s-bill-to-ban-under-16s-from-social-media">a members bill may also legislate</a> Age Assurance. The <a href="https://www.biometricupdate.com/202506/frances-push-for-age-restrictions-on-social-media-gains-urgency">French President Macron is demanding</a> social media controls for those under 16, and the US Supreme Court has supported state age-based restrictions on access to pornography in <a href="https://en.wikipedia.org/wiki/Free_Speech_Coalition_v._Paxton">Free Speech Coalition, Inc. v. Paxton</a>. By any measure, Age Assurance is the hot topic in Identity.</p><p>So we have demand &#8211; do we have a solution?</p><p>Hardly. We have underestimated the national importance of this opportunity and we lack understanding of the challenging context? Because of this we do not ask the correct questions. In this newsletter I <em>describe why<strong> Age Assurance</strong></em></p><ol><li><p><em><strong>is a strategic national issue,</strong></em></p></li><li><p><em><strong>has an extremely challenging context, </strong>and</em></p></li><li><p><em><strong>must answer some extremely difficult questions</strong></em><strong>.</strong></p></li></ol><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>A Strategic National Issue</h2><p><em><strong>A national digital infrastructure is as important as national physical infrastructures</strong></em>.</p><p>We spend more of our lives in the digital world than we spend driving our cars.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lcwH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lcwH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 424w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 848w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 1272w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lcwH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png" width="908" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:320,&quot;width&quot;:908,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42737,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/168354210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lcwH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 424w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 848w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 1272w, https://substackcdn.com/image/fetch/$s_!lcwH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81be99a6-e8ac-4ac7-bd15-5e32764b5952_908x320.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Digital Identity is central to a national digital infrastructure (the above diagram does not aim for completeness, but it shows Digital Identity as being the missing piece of the puzzle). Other digital infrastructure decisions, such as the nature of digital communications and the design of the Internet, have been made by technology companies, but decisions about Digital Identity are likely to be made by nations. And Age Assurance, a subset of Digital Identity, is the first major Identity decision for many countries.</p><p>Such Age Assurance decisions will either:</p><ul><li><p><strong>set a future direction</strong> for Digital Identity and digital infrastructure,</p></li><li><p>if narrowly focused, <strong>delay any progress</strong> on a broader Digital Identity solution, or</p></li><li><p><strong>create chaos</strong> if unsuccessful</p></li></ul><p>And it is decision time right now!</p><h2>The Challenging Context</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYNL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYNL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 424w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 848w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYNL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2573406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/168354210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cYNL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 424w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 848w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!cYNL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2acca558-71a2-44c4-aa13-83be9b65299c_1981x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The context is hugely challenging:</p><p><strong>Significant public issue. </strong>Identity processes are frustrating for people and costly for organizations. But these problems have been tolerated for a long time. Now the major problem is a lack of online identity services that results in social harm and fraud. Social harm results from a lack of online age assurance for social media, alcohol sales, and adult entertainment, and fraud results from a lack of online organisational authentication services for investment schemes. These are not just frustrations. <em><strong>This is a crisis</strong></em><strong>.</strong></p><p><strong>Size! </strong>While this might seem like stating the obvious, size is important. Take the Australian Age Assurance example &#8211; there is an expectation that this solution will enable around 25 million people to continue to use social media while keeping the under 16s safe. Note that means that the 25 million need to prove they are over 16. That is a lot of users, a lot of education, and a lot of infrastructure. These are not trivial decisions &#8211; <em><strong>the scope is all of society</strong></em>.</p><p><strong>No obvious solution</strong>. Identity is not simply an issue of applying a technique we know to new subject matter. Rather, Identity is a problem we are still struggling with. At its very basis is an individual proving to an organization who they are. Most other IT challenges involve collection and manipulation of data. Identity it is different &#8211; <em><strong>Identity is an inherently difficult problem</strong></em>.</p><p><strong>High Performance Bar. </strong>As I previously described in my newsletter <em><a href="https://www.newsletters.identity25.com/p/19-why-identity-systems-might-collapse">Why Identity Systems Might Collapse</a></em>, Age Assurance failures will not be tolerated. Even if a death is statistically negligible, if the solution that allowed it is perceived to be functionally negligent, then all hell will break loose and the discredited solution will be turned off. I agree &#8211; solutions cannot have error margins that allow for and expect collateral damage. That does not mean that age assurance solutions must be perfect, but it does mean that <em><strong>solutions must be designed for optimal performance</strong></em>.</p><p><strong>Immature Technology Environment. </strong>How mature are Identity technologies? As per IT&#8217;s general modus operandum, we are regularly bombarded with tales of brilliance and breakthroughs. Notwithstanding all this good news Identity is, by any count, an immature technology environment that lacks any common language and lacks any agreed approaches. For example, the Australian Age Assurance Technology Trial names possible technologies of Age Estimation, Age Interference, and Age Verification whereas New Zealand&#8217;s avowed path is Decentralized Identity. What a strange dichotomy. The EU is hoping that its Digital Identity Wallets pilots will converge on a common solution but it looks more like a fishing trip than a technical strategy. Apologists will find ways to justify the lack of a common language and suggest that current developments try to solve the same problem, but where is the compelling design? Identity, currently, is <em><strong>more noise than substance</strong></em>.</p><p><strong>Evolving standards!</strong> Why does a majority of the tech world now think that standards breed solutions? For discrete problems, such as USB standards, an industry can jointly design a solution. For complex problems, commercial players develop solutions and the industry later converges onto standards (e.g. payments). But for a large systemic problem like Identity, committee approaches are fraught. Trying to arrive at a design through standard development is simply nuts. For example, the travesty of mDLs (mobile Drivers Licenses) that do not include an authentication method! Standard-based approaches simply make Identity development so much harder. <em><strong>Standards do not breed solutions!</strong></em></p><p><strong>Profitable incumbents.</strong> The Identity Verification industry (Know Your Customer / Anti-Money Launder / Countering the Financing of Terrorism) are established and profitable. Cash cow? They have no need to change. They are comfortable with their cashflows &#8211; a reusable identity solution, one which would solve the Age Assurance problem, is not desired. <em><strong>Identity incumbents will resist change.</strong></em></p><p><strong>Big Tech is hovering</strong>. One cannot ignore big tech, as the major players have huge identity databases (mostly unverified) and control the technology base of Identity. To date, their initiatives have been restricted to leveraging their databases for low assurance identity (federated identity) and extending the reach of device-based identity for authentication (passkeys). While it is difficult to see how big tech can provide an optimal solution for high-assurance application-level Identity, they will no doubt try to extend the influence of their user databases and device/OS control. This is a question of sovereignty, and clearly every nation should be aiming to keep control over its citizens&#8217; identity information. <em><strong>National control of identity is at stake.</strong></em></p><p>So there is a large, societal crisis requiring a high-performance solution. There is no obvious solution and an immature industry that is either entrenched in current methods or bumbling around in standards while Big Tech waits for an opportunity to take control over critical national digital identity infrastructures.</p><p><strong>The context is challenging</strong>!</p><h2>Decision Questions</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qzlG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qzlG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 424w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 848w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 1272w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qzlG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png" width="1456" height="791" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:791,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2964756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/168354210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qzlG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 424w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 848w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 1272w, https://substackcdn.com/image/fetch/$s_!qzlG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc743275-f0fd-47c8-99cc-700ccbffb185_1980x1076.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When making a strategic decision, keeping all these contextual issues top of mind is not practical, so I refine the context down to some practical questions that can focus minds and that are sufficiently representative of the context. So this is a restatement of the context in questions:</p><h4>Is a national Identity infrastructure possible, and if so, is it desirable?</h4><p>Currently the assumption, which I think is correct, is yes. But the question should be explicitly considered to ensure that nations do not simply unknowingly fall into a national infrastructure scenario that cannot then be exited.</p><h4>Can an Identity solution be rapidly implemented for a country?</h4><p>Age Assurance cannot evolve like Payments has over 50 years &#8211; we have a crisis and we need a revolution. And revolutions must happen quickly to be successful. No matter what political pressures exist to start a project, taking 5 years to implement a national solution to a current crisis is not acceptable.</p><h4>Will the solution last?</h4><p>2 years, 5 years, 10 years, or more? Considering the opportunity cost and development cost, surely 10 years is a minimum. Countries do not go through such major changes very often, so it needs to stick.</p><h4>Will the solution be both useable and secure?</h4><p>The current Identity scenarios are zero-sum trade-offs. That is, if you want security, then you take a less useable process. And if you want a highly useable process solution, you accept lower security. Age Assurance will require highly useable processes and high security. Solutions now need to provide both aspects.</p><h4>Will the solution be publicly acceptable?</h4><p>And still there will be a question of public acceptability. The question needs to be asked: &#8216;will the public accept this?&#8217; And if the answer is no, then do not proceed!</p><h4>How will the industry be organized?</h4><p>Possibilities are 1) technology focused (e.g. Passkeys), 2) a central controlling membership body as there are for credit card schemes, and 3) every variant in between? This is a non-trivial question and needs to be answered up-front. It may be that a magic technology solves everything, but I do not remember this ever happening. So we will probably need some form of organizing.</p><h4>How will the Government be involved and will it actively manage the solution?</h4><p>Unfortunately, in many common-law countries, Identity development has started with the Government creating an Identity regulatory framework based upon the assertions that 1) a regulatory framework will lead to solutions, and 2) a regulatory framework can be devised that efficiently covers all possible solutions. Both assertions are obviously wrong. However, if the question is asked once a solution has been designed, the role of Government can be defined.</p><h4>Is the solution a long-term strategic Identity solution or a short-term tactical Age Assurance solution?</h4><p>This question is placed last in the list but should be a standing question throughout any design and development process, allowing the flexibility to both aim for a long-term solution and to revert to a short-term solution to meet the current Age Assurance Crisis.</p><h2>Decision Makers &#8211; Here are your questions to ask</h2><p>I started this newsletter by stating that we lack awareness of the national importance of Identity and the Age Assurance opportunity, and that we lack awareness of the current context.</p><p>Let&#8217;s hope that we can get past <strong>lame positivity</strong> and move on to <strong>pragmatism and critical thought</strong>. Let&#8217;s hope that decision makers include these questions:</p><ol><li><p>Is a national Identity infrastructure possible, and if so, is it desirable?</p></li><li><p>Can an Identity solution be rapidly implemented for a country?</p></li><li><p>Will the solution last?</p></li><li><p>Will the solution be both useable and secure?</p></li><li><p>Will the solution be publicly acceptable?</p></li><li><p>How will the industry be organized?</p></li><li><p>How will the Government be involved and will it actively manage the solution?</p></li><li><p>Is the solution a long-term strategic Identity solution or a short-term tactical Age Assurance solution?</p></li></ol><p>All the best</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[19. Why Identity Systems Might Collapse Under Their Own Ambition]]></title><description><![CDATA[Will identity ecosystems be too big to succeed?]]></description><link>https://www.newsletters.identity25.com/p/19-why-identity-systems-might-collapse</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/19-why-identity-systems-might-collapse</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 08 May 2025 10:14:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-kbo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-kbo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-kbo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-kbo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1937292,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.newsletters.identity25.com/i/163121105?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-kbo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!-kbo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87806d3f-c7a8-4d38-92da-ad936331e9ce_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#8220;Too big to fail&#8221; is something we all know, but will identity ecosystems be &#8220;too big to succeed?&#8221;</p><p>Some may succeed, but every aspiring identity ecosystem faces two brutal realities:</p><p>1.&#9;A single security failure can mean extinction</p><p>2.&#9;They will be relentlessly targeted by technologists, hackers, and the media</p><h1>Extinction</h1><p>Any transactional ecosystem has a value proposition based on the performance level it provides to consumers (e.g. service level, response time, security, cost).  If an ecosystem has a high value proposition, expectations will be sky high.  A single security failure will likely bring the whole edifice crashing down.</p><p>Think currency!  Currency has real value and is expected to be 100% secure.  What happens when a currency can be easily counterfeited &#8211; mayhem.  If it is generally easy to print your own money, no one will use the real stuff.  It has to be foolproof.  If counterfeiting became endemic, the only viable approach would be to reissue the currency.  That is why countries stay ahead of the game and don&#8217;t wait for the problems to occur.</p><p>Age assurance using a driver&#8217;s license does not have the same high value proposition.  It is accepted that it is not 100%  Yes, some fakes are made and some people abuse various systems using them.  But the costs of the negative outcomes is not so high.  So we tolerate them and the ecosystem remains operating.</p><p>Identity ecosystems occupy a unique space &#8212; not quite life-or-death like medical infrastructure, but close. They are foundational to trust, access, and legitimacy in digital interactions. If there is any question about an identity ecosystem&#8217;s trustworthiness, the fallout will be cataclysmic.</p><p>The best identity example I know of is Estonia, the poster child of good identity.  But in August, 2017 a vulnerability was found in the smartcards that were central to the Estonia identity solution and it was effectively shut down.  Fortunately, the cards themselves didn&#8217;t need to be reissued &#8212; but all certificates did. Queues formed at police stations as citizens rushed to complete the process.</p><p>Estonia made a pragmatic choice to halt operations because it really had no choice.  Once the vulnerability was known, there was every chance it would be exploited so they had to act.</p><p>For an identity ecosystem , one security failure can mean extinction.</p><p>Identity is an enticing domain for tech innovators &#8212; but it&#8217;s no easy game. The cost of getting it wrong is immense.</p><h1>A Target</h1><p>There are many people out there who may be quite keen to target a national identity ecosystem.</p><p>For threat actors, the kudos gained would be extreme.  These shady people gain satisfaction and notoriety through the amount of damage they can inflict &#8211; taking down a national identity ecosystem would be the ultimate hack.</p><p>Closely associated with threat actors are state-sponsored groups.  The geopolitical and economic disruption from disabling a nation&#8217;s identity infrastructure would be immense.  They will try!</p><p>At the same time, ethical hackers, researchers, and concerned citizens will test the system too &#8212; often with good intentions, hoping to catch vulnerabilities before real damage occurs.</p><p>And then there&#8217;s the media and social media &#8212; both serious and hysterical. In today&#8217;s world, everyone has a say.</p><p>I experienced this when I led the launch of Fastnet banking in the 1990s.  Bruce Shepherd was a well-known internet guru at the time and he raised some security concerns with the executive at the ASB predicting that phishing attacks would destroy our service within weeks of launch.  He had a point, of course, albeit somewhat exaggerated.  Rather than battle Bruce, I hired him to do a monthly security report.  I received one report.  We never heard from him again!</p><p>That was a different era.  Now the scale and diversity of attackers is far greater.  An identity ecosystem will be a target.</p><h1>Too Big to Succeed</h1><p>For identity ecosystems there is no room for error and everyone is watching.  Being overly ambitious will likely lead to fragile solutions.  This must be avoided &#8211; entrepreneurs, regulators, developers, and implementors of identity ecosystems must take their responsibilities seriously.</p><p>To design identity systems that won&#8217;t collapse under their own weight, we need to start not with abstract ideals, but with our current technology landscape &#8212; legacy infrastructure, the internet, consumer digital devices, and institutional IT assets. That&#8217;s where we&#8217;ll begin next time.</p><p>All the best</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[18. Is the EU Digital Identity Wallet Doomed?]]></title><description><![CDATA[Big projects often result in big failures...]]></description><link>https://www.newsletters.identity25.com/p/18-is-the-eu-digital-identity-wallet</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/18-is-the-eu-digital-identity-wallet</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Tue, 31 Dec 2024 03:36:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RyIN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RyIN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RyIN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RyIN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2961910,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RyIN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!RyIN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92251a8b-42e5-413a-a97b-462ade511286_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a lot at stake for the <a href="https://ec.europa.eu/digital-building-blocks/sites/display/EUDIGITALIDENTITYWALLET/EU+Digital+Identity+Wallet+Home">European Union (EU) Digital Identity</a><em><a href="https://ec.europa.eu/digital-building-blocks/sites/display/EUDIGITALIDENTITYWALLET/EU+Digital+Identity+Wallet+Home"> </a></em><a href="https://ec.europa.eu/digital-building-blocks/sites/display/EUDIGITALIDENTITYWALLET/EU+Digital+Identity+Wallet+Home">Wallet (EUDIW)</a> initiative. It is the biggest identity initiative on the planet.</p><p>While it has great aspirations, I think it is doomed from the start, as it fails to consider the small issue of implementation on the &#190; billion current EU smartphones.</p><h2>The Initiative</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6NSK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6NSK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 424w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 848w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 1272w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6NSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png" width="466" height="221" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:221,&quot;width&quot;:466,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19795,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6NSK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 424w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 848w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 1272w, https://substackcdn.com/image/fetch/$s_!6NSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76894b90-b90b-47df-9780-d1896ca7e71c_466x221.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>The EUDIW, created through legislation, will be the central technology for EU Digital Identity! This is the big play for the 2020s.</p><p>The EUDIW is driven by EU eIDAS regulation. eIDAS, or &#8220;electronic identification and trust services&#8221;, regulates electronic transactions. The initial 2014 regulation known as eIDAS 1.0 was revised to become eIDAS 2.0 in May 2024.</p><p>EIDAS 2.0 essentially legislates the EUDIW into existence and the EUDIW is central to EU Digital Identity.</p><p>This is no ordinary wallet: it is the fundamental technology for Identity for decades to come.</p><h2>The Pilots</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c_LM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c_LM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 424w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 848w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 1272w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c_LM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png" width="545" height="177" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:177,&quot;width&quot;:545,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21514,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c_LM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 424w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 848w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 1272w, https://substackcdn.com/image/fetch/$s_!c_LM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3a6f76-fbb0-4692-a9e5-a47716f8a26e_545x177.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>To support this, the EU is financing four pilots to the tune of 40-50 million euro. The pilots consider different use cases:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ytv5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ytv5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 424w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 848w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 1272w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ytv5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png" width="609" height="372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:372,&quot;width&quot;:609,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ytv5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 424w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 848w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 1272w, https://substackcdn.com/image/fetch/$s_!Ytv5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640261d-3c15-48ff-9fd2-88765d18f64b_609x372.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two things stand out:</p><blockquote><p><strong>a focus on user functionality</strong> &#8211; the structure is clearly the use of identity as opposed to the underlying practicality of implementing identity.</p><p><strong>a cast of thousands</strong> &#8211; 100s of large organizations, both governmental and commercial, and literally thousands of people involved. This is no &#8216;skunk works&#8217; driving to a rapid solution; this is an EU megaproject.</p></blockquote><h2>Making the EUDIW Secure</h2><p>Now, just to be clear, the EUDIW is the central technology that holds all Personal Identity Information (PII).  The EUDIW is a decentralized approach in which the wallet holder goes from EU country to EU country freely sharing their PII as they see fit.  </p><p>So the EUDIW needs to be secure.</p><p>The small issue of making the EUDIW secure is described in the Architecture and Reference Framework 1.4. Section <a href="https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/blob/main/docs/arf.md">4.3 Architecture Types</a> states that:</p><p>&#8220;&#8230;at least four different types of architecture for the EUDI Wallet Solution can be identified, each leveraging a different type of Wallet Secure Cryptographic Device (WSCD):</p><ol><li><p><strong>Remote Wallet Secure Cryptographic Device (Remote WSCD):</strong> In this architecture, the Wallet Secure Cryptographic Device is situated remotely, separate from the user's device, for example - implemented by the Wallet Provider using an HSM.</p></li><li><p><strong>Local External Wallet Secure Cryptographic Device (Local External WSCD):</strong> If a device lacks sufficiently secure hardware, such as a secure element, external hardware components like smartcards may be necessary to enhance security. This architecture involves an external Wallet Secure Cryptographic Device that is connected to, or interacts with, the User's device, to provide cryptographic functions, for example - a hardware token or smart card.</p></li><li><p><strong>Local Wallet Secure Cryptographic Device (Local WSCD):</strong> This architecture refers to a scenario where the Wallet Secure Cryptographic Device is integrated directly within the User's device. This includes solutions like eSIM/eUICC and eSE. In these scenarios, the WSCA (e.g., a Java Card applet) might be deployed by the Wallet Provider. Other examples are based on native solutions, such as StrongBox (Google) and SecureEnclave (Apple), in which access to the WSCD is facilitated via the operating system of the User device.</p></li><li><p><strong>Hybrid architecture:</strong> This architecture combines two or more of the previous three approaches.&#8221;</p></li></ol><h2>The Implementation Problem</h2><p>Now here is the problem &#8211; if the EUDIW is going to be useful, it needs to work for people and those people in the EU have roughly &#190; billion smartphones. Remember, we cannot leave anyone out. So how will these solutions fit the current &#190; billion smartphones:</p><ol><li><p><strong>Do the security centrally</strong> &#8211; well, it might work but why bother? If the whole solution revolves around central security infrastructure why not use a central infrastructure for the whole solution? Why would anyone come up with such a complex solution when a simpler solution is available?</p></li><li><p><strong>External device</strong> &#8211; you must be joking. We will get a device that can integrate with &#190; billion smartphones. Plug and play for 750,000,000 different brands, models, OS versions etc! Not this decade and unlikely to be in the next either!</p></li><li><p><strong>Use the security of the smartphone</strong>. I&#8217;ve seen that tried and failed when simply using one brand of smartphone. Trying to get uniformity of smartphone OSes is the stuff of science fiction and trying to retrofit 750,000,000 smartphones not possible.</p></li><li><p><strong>Any two of three</strong> &#8211; even harder!</p></li></ol><h2>The EUDIW Project will fail to reach its goals</h2><p>The EUDIW project is playing in the fun end of Digital Identity, imagining all the neat and wonderful use cases that can please everyone. Fancy that &#8211; some bureaucrats coming up with some good PR!</p><p>The actual challenging aspect is making it work for a large installed base of smartphones and that is inherently difficult. <strong>The implementation challenge is not being faced and the EU has, as yet, no answer.</strong> </p><p>And, I maintain, it has no answer because there is no answer!  It is inherently problematic to secure PII on personal digital devices.</p><h2>The partial rescue options</h2><p>If the EUDIW fails to deliver in full, I see two possibilities:</p><ol><li><p>the EU gives it all to Apple and Google</p></li><li><p>the EU simply declares EUDIW a success based on lesser functionality</p></li></ol><p>Now Apple and Google already own a lot of us, so they would no doubt be keen to own all of us.  Passing Digital Identity to them would simply formalize the relationship by passing over the keys.  No need for governments to worry about the future of identity! Of course, this would be calamitous and must be avoided.  If Self-sovereignty was the goal, we do not want to fall back to no sovereignty at all.</p><p>The second option is more likely.  A lesser EUDIW functionality will be a signed document on a smartphone. For example a mobile drivers license (mDL). Such technology has benefits as the license can be certified as being authentic but it is also limited, just like physical document, as it does not identify and authenticate the person. It is simply a copy of a credential.</p><p>But a document on a smartphone is not a Digital Identity solution!</p><p>This will be interesting viewing!</p><p>All the best for New Year</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[17. Digital Identity: Which Way José?]]></title><description><![CDATA[A year on, there has been little progress with Digital Identity, but at last there are some indications that the strategic question will come into focus...]]></description><link>https://www.newsletters.identity25.com/p/digital-identity-which-way-jose</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/digital-identity-which-way-jose</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 19 Dec 2024 06:18:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!H72X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H72X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H72X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!H72X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!H72X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!H72X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H72X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2527450,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H72X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!H72X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!H72X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!H72X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7eb8153-cbd4-4b19-b428-64fde516cf81_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Digital Identity 2024: a lot of talk, more regulation, EU pilots starting up, Passkey expansion, but little progress towards actually coming up with an answer to the big question:</p><p><em><strong>&#8220;how do we implement a national identity infrastructure?&#8221;</strong></em></p><p>But there is hope - recent pronouncements in three different countries suggest that this broad question is coming into focus.  The evidence is somewhat circumstantial but I invite you to make up your own mind about Australian Age Assurance, Aotearoa New Zealand Age Assurance, and a US pivot to Identity Authorization Networks.</p><p>And I invite you to think about the future&#8230;</p><h2>Australian Age Assurance</h2><p>Isn&#8217;t it great when politicians legislate something into existence - it removes all that messiness of Business Cases and Net Present Value analyses.  And that is what the Albanese Government has done by decreeing that Age Assurance must be live by December 2025 and initiating an <a href="https://ageassurance.com.au/">Age Assurance Trial</a> that is due to report back by June 2025.</p><p>Now Age Assurance is an identity problem at heart - the challenge is to authenticate a person and check that their age (a credential) is within range.  This is the goal of this trial which will consider three technology options:</p><ol><li><p><strong>Age Verification</strong>: like Identity Verification, images are taken of identity documents and combined with live video of the person to confirm the individual is of a certain age (as recorded in their identity document such as a drivers license)</p></li><li><p><strong>Age Estimation</strong>: utilizes sensory information (face, movement, voice) to estimate the age of a person</p></li><li><p><strong>Age Inference</strong>: highly general big data approach of using broad sources of information to infer age</p></li></ol><p>It&#8217;s good to see progress, but:</p><ul><li><p>Clearly Age Verification has useability challenges - there are a lot of moving parts and it takes time.</p></li><li><p>Clearly Age Estimation and Age Inference have accuracy challenges - they have the words &#8216;estimation&#8217; and &#8216;inference&#8217; in their titles for a reason.</p></li><li><p>Are these the only alternatives?  Why has the trial limited its solution scope?  See below for two more options.</p></li></ul><h2>Aotearoa New Zealand Decentralization</h2><p>Over the ditch in Aotearoa New Zealand, the Department of Internal Affairs has established the <a href="https://www.dia.govt.nz/Trust-Framework-Authority">Trust Framework Authority</a> (TFA) to regulate the <a href="https://www.dia.govt.nz/Trust-Framework">Digital Identity Services Trust Framework</a> that supports the accreditation of Digital Identity service providers.  </p><p>The TFA recently added some <a href="https://www.dia.govt.nz/Trust-Framework-for-Digital-Identity-Resources">resources</a> including a <a href="http://chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.dia.govt.nz/diawebsite.nsf/Files/Trust-Framework/$file/DITFA-board-user-journey-Sam.pdf">use case for age assurance</a>!  This use case is a <strong>decentralized solution</strong> which is unsurprising as the TFA states in <a href="https://www.dia.govt.nz/Trust-Framework-for-Digital-Identity-Key-Concepts-and-Principles#personal-information">Key concepts and principles</a> that: &#8220;Personal information will not be held in a centralised database &#8230; The rules and regulations for the trust framework support a decentralised approach to the holding and sharing of information&#8221;.</p><p>Great, but one can only ask:</p><ul><li><p>Why has Australia not recognized the one technology option that New Zealand has adopted as the chosen solution for Age Assurance?</p></li><li><p>Why is New Zealand so confident that this solution will work when there are no functioning solutions yet implemented?</p></li></ul><h2>Leading Research Agency in USA finds IANs</h2><p>I have been a great fan of <a href="https://liminal.co/">liminal.co</a> &#8212; for many years they have covered the big strategic issues of Digital Identity, and they are now recognizing <strong><a href="https://liminal.co/news/role-of-identity-authorization-networks/">Identity Authorization Networks</a></strong> (IANs) as the next emerging trend.  </p><p>In their report, they compare IANs to BankID in Scandinavia and as the name suggests, find that networked organizations is a central aspect of such solutions.  IANs  will provide a &#8220;scalable, cost-efficient, and user-friendly solution that securely links real-world identities to online actions.&#8221;  Heady stuff but:</p><ul><li><p>why do neither Australia or New Zealand recognize IANs?</p></li></ul><h2>Identity 2.0, Identity 2.5, and Identity 3</h2><p>All these initiatives fit into the framework of identity evolution that I described some time ago:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a_N4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a_N4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 424w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 848w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 1272w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a_N4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png" width="1456" height="850" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:850,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175713,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a_N4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 424w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 848w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 1272w, https://substackcdn.com/image/fetch/$s_!a_N4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9188db2-c2f4-4fbc-9206-99cde6d90f47_3201x1869.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So, three fundamentally different approaches, two of them by governments of neighbouring countries.</p><h2>My Questions to You</h2><p>The first obvious question is &#8220;<strong>how can all these three initiatives be so widely different in a world of instant access to information and expertise?</strong>&#8221;  This is a most bizarre situation and while I know the apologists that will say this is normal and good and all that type of excuse-mongering, the bottom line is that we all (especially governments) should be better at defining the options for Digital Identity.</p><p>My second question is &#8220;<strong>if we do not have a full view of all the options, how can we make good strategic choices?</strong>&#8221;  These are important issues and we should ask why we are not better informed.  Someone ought to insist on some better strategic thinking before we leap into decision mode (maybe it is already too late?).</p><p>My third question is &#8220;<strong>Which way Jos&#233;?</strong>&#8221;  I expect the answer must be Identity 2.5 Networked simply because it is the only cost effect, secure, and useable approach.  I just hope we have rational decision making processes.</p><p>Best wishes for the holiday season,</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[16. Will decentralized identity work?]]></title><description><![CDATA[Will decentralized identity really work? Everything is opinion at present as there are many open questions.]]></description><link>https://www.newsletters.identity25.com/p/16-will-decentralized-identity-work</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/16-will-decentralized-identity-work</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Fri, 28 Jun 2024 05:34:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nno3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nno3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nno3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!nno3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!nno3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!nno3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nno3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2368266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nno3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!nno3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!nno3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!nno3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ee357e2-4306-4a7a-9679-bec778d2058e_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is an interesting &#8216;decentralized identity conversation&#8217; starting here on Substack and if you are just catching up - here&#8217;s where we are:</p><ol><li><p>Phil Windley wrote&nbsp;<a href="https://substack.com/home/post/p-145290516">Decentralized Identity Comes of Age</a></p></li><li><p>I responded with&nbsp;<a href="https://www.newsletters.identity25.com/p/yeah-yeah-yeah-yeah-yeah-nah">Yeah, yeah, yeah, yeah, yeah, nah</a>, in which I asked:</p><p><em>Is there someone who can distil all that amazing work into a decentralization design we can all understand?</em></p></li><li><p>And Phil obligingly answered in his post&nbsp;<a href="https://substack.com/home/post/p-145723119">What Is Decentralized Identity?</a></p></li></ol><p>I learnt a lot about decentralization through this last post, but I still had one of those nagging doubts about the efficacy of the solution.  As I reflected on Phil&#8217;s post I recognized that the &#8220;will it work?&#8221; question needs to cover more than design.&nbsp; Specifically we need:</p><p><strong>design</strong> (a given requirement for any new solution) - a topography of people and technology, including interactions and information.</p><p><strong>security</strong> (fundamental to the identity challenge) - how confidential data is secured, and why the solution is secure.</p><p><strong>implementation</strong> (difficult for any solution that aims to become a standard) - how the solution can be implemented for large user populations.</p><p>So here is my take on the challenges for decentralization in these important areas.</p><h3>Design</h3><p>In Phil&#8217;s response, the decentralized design still includes Decentralized Identifiers (DIDs), but two additional elements, digital wallets and verifiable credentials, have been identified as &#8216;needed&#8217;.</p><p>These additions show that decentralized identity is an evolving discipline and so there is much to ask, including two fundamental design challenges:</p><h4>The First Design Challenge - doing the hard bit first!</h4><p>I&#8217;ll use my model of the identity process to illustrate this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9lLk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9lLk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 424w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 848w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 1272w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9lLk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png" width="406" height="124.92307692307692" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:448,&quot;width&quot;:1456,&quot;resizeWidth&quot;:406,&quot;bytes&quot;:85283,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9lLk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 424w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 848w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 1272w, https://substackcdn.com/image/fetch/$s_!9lLk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc75058e4-f438-48ad-b9f0-045e67a058fd_2417x743.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This model shows that <em>identification and authentication</em>, i.e. saying who you are and proving that you are who you say you are, precede utilizing <em>credentials</em> for some purpose.&nbsp; No identity solution can be complete without both these components.</p><p>Phil&#8217;s explanation shows a digital wallet and describes how autonomous software components could potentially interact and exchange credentials securely.&nbsp; But we still do not know how access to the wallet is controlled.&nbsp; If this is not &#8216;the&#8217; big identity issue of how the actual person is identified and authenticated, then what is?</p><p>Yes, the credential use is there, but surely an identity solution needs to be more than that?&nbsp; If access to the digital wallet is predicated on the security of the smartphone, doesn&#8217;t that make the solution simply a distributed credential solution, which raises the obvious question of &#8220;why bother?&#8221;</p><h4>The Second Design Challenge - a macro hybrid solution?</h4><p>At the macro level, Phil&#8217;s design shows a decentralized identity utilizing other identity solutions to load their own structures with credentials.&nbsp; If this is the case, the macro view of multiple complementary identity solutions should be made explicit and the design rationale for such a hybrid solution justified.&nbsp; </p><p>A hybrid solution may &#8216;work&#8217; but is that what we really need or want?</p><h3>Security</h3><p>This is clearly fundamental to an identity solution. &nbsp;Decentralization based on a digital wallet with autonomic identifiers (local storage, if I have read it correctly) requires both an app and local data to be secured.&nbsp; How is this achieved?&nbsp; Does it rely on the security provided by the relevant smartphone operating system, does it utilize the hardware cryptographic capabilities of the smartphone, or is there some other bespoke approach to security?</p><p>This is important, and remember that much of decentralization is predicated on the lack of trust for major corporations that leak identity data all too often.&nbsp; Surely decentralization should not be just another leaky solution?</p><p>Is there a relatively simple explanation of how security is achieved by decentralization?</p><h3>Implementation</h3><p>If you want to try something really hard, try implementing a complex software solution on every smartphone in a country. &nbsp;That is, within reason, support every model sold in the last decade and still being used.&nbsp; That is every operating system version and every variant of crypto support hardware.&nbsp;</p><p>For an app that is simply a front for cloud-based data, implementation over multiple smartphone variants is relatively simple as the app is simply a presentation layer.&nbsp; For a decentralized digital wallet, the challenge of implementing complex infrastructure for a population is extreme.</p><p>How will decentralization achieve this?</p><h3>Summary</h3><p>The current status of the decentralization model appears to remain somewhat conceptual rather than contextual.&nbsp; That is, the concept is a good idea and easy to buy into, but the contextual challenge of making it work is being left to the developers!</p><p>This status is confirmed by the lack of working prototypes.  And if decentralization were more fully developed, we should expect to see such prototypes and we don&#8217;t!</p><p>So, for me, <strong>&#8220;Will it work?&#8221; remains an open question, </strong>and yeah, yeah, yeah, yeah, yeah, nah is still a distinct possibility.</p><p>As you have  read this newsletter, and perhaps others, <strong>it would be great to get your thoughts.   </strong>Please comment, below, or write your own post and link back - whatever works for you.&nbsp;</p><p>Until the next time ...</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[15. Yeah, yeah, yeah, yeah, yeah, nah]]></title><description><![CDATA[Is the history of decentralization patterned after the stock market?]]></description><link>https://www.newsletters.identity25.com/p/yeah-yeah-yeah-yeah-yeah-nah</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/yeah-yeah-yeah-yeah-yeah-nah</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sat, 15 Jun 2024 04:29:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T8TS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T8TS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T8TS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 424w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 848w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T8TS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png" width="1456" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2928194,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T8TS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 424w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 848w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!T8TS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8aa82e0-be80-4ef5-88bf-67eaeff5aa84_1956x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>True Story.</p><p>A good friend of mine, Denis, put me onto a UK stock that was going to fund his retirement.&nbsp; So, in I went, boots and all.&nbsp; It was a bit up and down, but we believed.&nbsp; We believed.&nbsp; It started to slide.&nbsp; Concerned, I left Denis a message saying &#8220;what&#8217;s up&#8221; and Denis, confidently, left me a message saying &#8220;I have total confidence in &#8230;&#8221;.&nbsp;&nbsp; Phew.&nbsp; A week later I rang again, and Denis began with &#8220;I sold the lot&#8230;&#8221;.&nbsp;</p><p>Will decentralized identity go the same way?</p><p>In his recent post, &nbsp;'<a href="https://www.technometria.com/p/decentralized-identity-comes-of-age">Decentralized Identity Comes of Age</a>&#8217;&nbsp;,&nbsp;Phil Windley wrote that he feels that <strong>decentralization has reached its tipping point</strong>.&nbsp; Phil was at the European Identity Conference and observed that &#8216;decentralized identity' is moving out of the &#8216;geek' space into &#8216;mainstream' space.&nbsp;</p><p>That is intriguing!</p><p> I do agree with Phil&#8217;s assertion that decentralization will be a wonderful solution that transforms so many of today&#8217;s problematic identity processes.  Not only that, but that view is shared by many people, as Phil showed - decentralization is the nirvana for identity. </p><p>Which brings me to the practical. As decentralization reaches its fulfillment, it only seems reasonable to ask &#8220;<strong>will it work?</strong>&#8221;</p><p>My challenge to the decentralization community is for them (someone) to explain how it works in relatively simple and reasonable terms.&nbsp; I say relative because identity is not simple, so we should not expect simple solutions.&nbsp; But &#8230; we should expect to see a design that can be understood by the informed, which probably means you and me.&nbsp; We should not be expected to look at a whole bunch of code and then determine how it works.&nbsp; Also, we need to see a design that is more than a list of desirable outcomes.&nbsp;&nbsp;<strong>We need to see a tangible design.</strong></p><p>The Internet Identity Workshop is in its 20th year and has produced so much and shaped so much more. Could I ask for them in the name of &#8217;Steve' for just &#8216;one more thing&#8217;?</p><p>Is there someone who can distil all that amazing work into a decentralization design we can all understand?</p><p>Or is this like my UK stock journey &#8211;&nbsp;<strong>yeah, yeah, yeah, yeah, yeah, yeah, nah?</strong></p><p>I promise you that the nah moment leaves one feeling a bit empty&#8230;</p><p>Regards</p><p>Alan</p><p>p.s. &#8216;Yeah, nah&#8217; is a common expression in New Zealand Aotearoa.  When used in conversation it often has lots of yeahs before the nah.  In the end, It always means no.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[14. Verifiable Credentials or Verified Transactions?]]></title><description><![CDATA[We are heading towards verifiable credentials but verified transactions are more important!]]></description><link>https://www.newsletters.identity25.com/p/14-chapter-14-verifiable-credentials</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/14-chapter-14-verifiable-credentials</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sun, 12 May 2024 02:03:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IZkm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IZkm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IZkm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IZkm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1090982,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IZkm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!IZkm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9f3bf4b-33d7-41a5-824c-eca608071f82_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Verifiable Credentials (VCs) will be forgotten and Verified Transactions (VTs) will be the norm</strong>.&nbsp; How&#8217;s that for stirring the pot!&nbsp; In this newsletter I&#8217;ll briefly discuss the technology basis for both, why Verifiable Credentials have limited use and are dangerous, and why Verified Transactions have many uses and will become the norm.</p><h1>Technology Basis</h1><p>It is all about public key cryptography (also called public/private key cryptography and asymmetric cryptography).&nbsp; You use it every time you use a browser - it is the basis for SSL secure communications between Internet browsers and servers.&nbsp; It works and it is proven.</p><p>Besides enabling secure communications, public key cryptography also supports the digital &#8216;signing&#8217; of documents.&nbsp; That is, such documents can be signed digitally and can then be digitally verified.&nbsp; This tech has been around for a long time, it works, and it can be used to sign both VCs and VTs.</p><h1>Verified Credentials</h1><p>Let&#8217;s first look at VCs.&nbsp; These are slated to be the next big thing for Identity, but I maintain that VCs are limited to data sharing, and I maintain that VCs are dangerous when stolen or lost because they have real value.</p><h3>Data sharing only &#8211; not a full Identity solution</h3><p>The major limitation is that VCs are not a full Identity solution!&nbsp; Do you remember this:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v1Hu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v1Hu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 424w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 848w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 1272w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v1Hu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png" width="1456" height="448" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6ec330f-a329-48ad-9e5e-143022895130_2417x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:448,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85283,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v1Hu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 424w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 848w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 1272w, https://substackcdn.com/image/fetch/$s_!v1Hu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6ec330f-a329-48ad-9e5e-143022895130_2417x743.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>VCs could clearly be part of the right-hand side.&nbsp; That is, they could act as a standardised way for sharing data with the added benefit that the receiver could trust the validity of the credential.&nbsp; This would have more applicability for decentralised solutions where trust needs to be established for every transaction, whereas networked solutions, with connected &#8216;already trusted&#8217; parties, does not have the same need (i.e. if it is a trusted source the data should also be trusted).</p><p><strong>But a VC does not do authentication.&nbsp;</strong> Think about a person holding a university degree in front of you.&nbsp; The name identifies them and the wax seal gives confidence that this is a valid degree.&nbsp; But is the person holding the degree the person named on the degree?&nbsp; There is no way to know.&nbsp; The hard bit of identity, authentication, is not covered at all.&nbsp; VCs are the same as a physical university degree &#8211; they are not an authentication solution.</p><p>Now, some clever person will likely respond suggesting that the credentials within the VC can be used to authenticate the holder of the credential.&nbsp; But putting your secret password or your biometrics into some document you share with all and sundry is clearly not a good idea.&nbsp; Keep the secrets as secrets.</p><p>So, VCs are only part of Identity and they are not the hard part of Identity!&nbsp; The hard part is, of course, authenticating yourself to someone who doesn&#8217;t know you, and VCs do nothing for that problem.</p><h3>The cost of stolen credentials</h3><p>Currently a fuss is made when credentials are stolen or inadvertently made public, but the fallout will be minor compared to that in a world of VCs.</p><p>We know that there are data breaches and I take such breaches seriously.&nbsp; But often the stolen data is commonly available!&nbsp; Does anybody remember the telephone box with name, address, and telephone number?&nbsp; Much of the data stolen is exactly this data.&nbsp; And so, the reason data breaches do not condemn all those affected to lives of purgatory is because the data is probably available anyway.</p><p>In a world of VCs all that changes.&nbsp; VCs will be lost and stolen due to leaky organizations and leaky digital wallets.&nbsp; This will not be an issue in a perfect world where authentication is done properly and identified person strongly verified against the identity in the VC.&nbsp;</p><p>But one can see the situations developing where nefarious individuals will attempt to use stolen VCs either through associating them with a similar name or by aggregating them to suggest a certain individual.&nbsp; And if the technology becomes ubiquitous people will test the boundaries.&nbsp;</p><p>The fundamental problem is that, because it is verifiable, the VC is valuable but it can be copied infinite times.&nbsp; It&#8217;s a bit like making millions of perfect copies of the physical university degree I mentioned above.&nbsp; Each one is &#8216;real&#8217;.&nbsp; What can then be trusted?</p><h3>Are VCs fools gold?</h3><p>We do not yet know, but VCs have more challenges than simply being implemented.&nbsp; By their very nature they can only be part of an Identity solution, but they are not an essential part, and when implemented they may create more problems that they solve.&nbsp;</p><h1>Verified Transactions</h1><p>Recent discussions in the Anti-Money Laundering / Countering the Financing of Terrorism / Know Your Customer / Customer Due Diligence (AML / CFT / KYC / CDD) world has highlighted to me that we live In a world of compliance, and how important cost effective compliance is now and will be in the future.</p><p>Part of that compliance is an audit function, and organizations I have discussed this with confirm that when audited they often fall back on physical records.&nbsp; In 2024! &nbsp;And, of course, many of the AML processes they execute are performed by third parties.</p><p>So why not record the organization requiring the AML process, the person who is the subject of the AML process, and the result, and sign it?&nbsp; That would seem to be a practical and useful application of public key cryptography.</p><h1>Weighing it up</h1><p>VCs are probably essential for the decentralized Identity movement.&nbsp; We have Decentralized identifiers (DIDs), Digital Wallets, and now VCs that presumably will work in unison.&nbsp;</p><p>But for any other Identity solution, <strong>VCs will not solve the basic Identity challenge of authentication, while adding another layer of complexity and possibly creating other long-term issues.</strong></p><p><strong>VTs could solve a current problem.</strong></p><p>If you believe in the decentralized model you need to believe in VCs.&nbsp; If you believe in a networked model, you don&#8217;t need VCs and VTs are a real opportunity.</p><p>What do you think?</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[13. Will passkeys be a bed of roses?]]></title><description><![CDATA[Surely being promoted by Google, Microsoft, and Apple, passkeys must be the next big thing!]]></description><link>https://www.newsletters.identity25.com/p/13-will-passkeys-be-a-bed-of-roses</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/13-will-passkeys-be-a-bed-of-roses</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 29 Feb 2024 05:21:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!APZV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!APZV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!APZV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!APZV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!APZV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!APZV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!APZV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2967890,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!APZV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!APZV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!APZV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!APZV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d789f03-a0d4-4f72-94ca-edff1cdadf30_1792x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Intro</h1><p>Passkeys, announced by Apple, Google, Microsoft, and the FIDO Alliance in May 2022, are a replacement for passwords.&nbsp; In this newsletter I will:</p><ul><li><p>show where passkeys fit</p></li><li><p>describe why we need passkeys</p></li><li><p>present a passkey primer because how they actually work is quite important</p></li><li><p>list some key problems with passkeys</p></li><li><p>suggest that passkeys are far from a complete solution and not THE answer.</p></li></ul><h1>Where do passkeys fit?</h1><p>Passkeys replace passwords.&nbsp; They are a unique cryptographic key for each website or app that a person signs onto.&nbsp; Like passwords, passkeys are a form of authentication.&nbsp; Remember this diagram (from my <a href="https://www.newsletters.identity25.com/p/3-identity-fundamentals">newsletter 2</a>):</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TDiB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TDiB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TDiB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png" width="534" height="167.97527472527472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:458,&quot;width&quot;:1456,&quot;resizeWidth&quot;:534,&quot;bytes&quot;:90351,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TDiB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!TDiB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749ba9ee-839e-4996-bb19-f606990f1a3b_2363x743.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>So, passkeys are not a full identity solution, but they perform a fundamental function within Identity, this being authentication.</p><p>And passkeys fit in a niche - they are not the saviour for all identity scenarios:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CbQf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CbQf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 424w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 848w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 1272w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CbQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png" width="708" height="484.80494505494505" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:997,&quot;width&quot;:1456,&quot;resizeWidth&quot;:708,&quot;bytes&quot;:460527,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CbQf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 424w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 848w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 1272w, https://substackcdn.com/image/fetch/$s_!CbQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F058bb5d3-181f-42a1-ab9a-1ce5f389e93d_2986x2045.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Passkeys work on-line for established relationships (2-party transactions).&nbsp; That is, they work when you are signing on to an existing account you opened sometime before, for example a bank account.&nbsp; They do not have any relevance for in-person or on-telephone situations, and they do not have any relevance when establishing relationships (3-party transactions) such as Know Your Customer, when you are opening an account.&nbsp; For a full explanation of this framework, see my <a href="https://www.newsletters.identity25.com/p/4-identity-performance-2-party">newsletter 3</a> and my <a href="https://www.newsletters.identity25.com/p/5-identity-performance-3-party">newsletter 4</a>.</p><p>So passkeys are limited in function (authentication) and in scope (on-line accounts already opened).</p><h1>Why do we need passkeys?</h1><p>Secure on-line access is a real problem now, so passkeys are very relevant, even if they do not solve every problem we have.&nbsp; The culprit is a particular type of phishing &#8212; on-line username and password phishing. &nbsp;That is, you are tricked onto a site and give away your username and password. &nbsp;This is a problem and it is why so many sites now have moved to multi-factor authentication (MFA).&nbsp; But even with MFA, phishing is still possible, even if it is less prevalent.</p><p>The Fast ID Online Alliance (FIDO) has a solution they call 2FA for second factor authentication.&nbsp; FIDO 2FA is provided by a hardware device called a FIDO security key that often looks like a USB flash drive.&nbsp; These devices use public key cryptography to provide very high levels of security. &nbsp;But they are costly and they are painful to replace, and so they have not taken off.</p><p>We need something better, so FIDO, Google, Apple, and Microsoft invented passkeys that go beyond FIDO 2FA.</p><h1>A passkey primer</h1><p>So how do they do it?&nbsp; I&#8217;ll discuss both the functionality, and how that functionality is implemented.</p><h3>Passkey Functionality</h3><p>The three principal processes involving passkeys are:</p><ol><li><p>setting up a passkey</p></li><li><p>signing on using a passkey</p></li><li><p>administering of passkeys</p></li></ol><h4>1. Setting up</h4><p>You start by signing off the old way.  Then, somewhere in the app or website, you select an option to set up a passkey.  You are asked if you want to save a passkey for the site:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oRM7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oRM7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 424w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 848w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 1272w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oRM7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png" width="419" height="484.1777777777778" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:572,&quot;width&quot;:495,&quot;resizeWidth&quot;:419,&quot;bytes&quot;:17511,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oRM7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 424w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 848w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 1272w, https://substackcdn.com/image/fetch/$s_!oRM7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ad5816d-5c51-41b2-8685-d21b41566e55_495x572.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You confirm saving the passkey by entering your Windows Hello PIN (this is your PC PIN - the one you might use when you boot your PC) and Windows confirms the passkey is saved.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_PsO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_PsO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 424w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 848w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 1272w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_PsO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png" width="471" height="330" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:330,&quot;width&quot;:471,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10109,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_PsO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 424w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 848w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 1272w, https://substackcdn.com/image/fetch/$s_!_PsO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f976f3-3926-4f3b-8472-bdc2382e506e_471x330.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>2. Signing on</h4><p>This is part of a signon page presented by a Chrome browser running on a Windows 11 PC.   You don&#8217;t enter anything, you simply click in the signon username box.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_lzu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_lzu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 424w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 848w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 1272w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_lzu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png" width="487" height="440.3013698630137" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:330,&quot;width&quot;:365,&quot;resizeWidth&quot;:487,&quot;bytes&quot;:10732,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_lzu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 424w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 848w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 1272w, https://substackcdn.com/image/fetch/$s_!_lzu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a470b71-944d-4370-b45b-12c8ee0c0f87_365x330.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first thing to notice is that passkeys work a bit like a password manager!&nbsp; You click in the signon username box and&nbsp;the browser gives you passkey options (if they have been setup), in the same way as a password manager gives you username / password options.&nbsp; There is nothing to remember!</p><p>So you activate a signon field in the website, confirm the use of the passkey, and you are in.&nbsp; Well almost &#8211; there is a second step:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Jvj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Jvj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 424w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 848w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 1272w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Jvj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png" width="556" height="472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:472,&quot;width&quot;:556,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15546,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Jvj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 424w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 848w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 1272w, https://substackcdn.com/image/fetch/$s_!5Jvj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0af28691-aa41-402f-bb51-0fd5edc6bf1a_556x472.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this scenario, the passkey is secured by Windows Hello which validates the use of the passkey, in this case through the entry of a PIN (there are alternative ways: face and fingerprint).</p><p>And note that a passkey functions very much like a password manager with MFA, in that both require an initial selection followed by a second factor of authentication.</p><p>An advantage of passkeys is that the two steps are local to one device, in this case a PC.  There is no need for a separate smartphone to confirm the signon.</p><h4>3. Passkey administration</h4><p>On a Windows 11 PC there are three places for passkey administration:</p><ol><li><p>the application itself</p></li><li><p>the Google Password manager</p></li><li><p>Windows 11 settings</p></li></ol><p>The applications I have seen list the passkeys and allow them to be deleted.&nbsp; The Google password manager simply defaults through to Windows 11 Settings below:&nbsp; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tFuq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tFuq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 424w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 848w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 1272w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tFuq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png" width="421" height="487" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:487,&quot;width&quot;:421,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20089,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tFuq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 424w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 848w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 1272w, https://substackcdn.com/image/fetch/$s_!tFuq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397429de-b849-4997-9b5b-f34b7d20c1d4_421x487.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Passkeys are embedded in the Operating System (OS)</h3><p>In these examples, <strong>the passkey is saved within Windows 11, the Microsoft OS and the passkey is tied to a device</strong>.&nbsp; Yes, that is important!</p><p>So, while passkeys function in a similar manner to password managers for the user (i.e. they make the process somewhat automated), the implementation is totally different (i.e. cloud for password manager, local OS for passkeys).&nbsp; This has implications as described below.</p><h1>And the problems</h1><p>My analysis of passkeys above, and my reading, suggest that <strong>passkeys are user friendly and totally secure against phishing</strong>.&nbsp; That is, you cannot phish a passkey.&nbsp; Great - one big tick there.  So what&#8217;s the problem?</p><h4>Passkeys don&#8217;t stop phishing attacks!</h4><p>Hold on, didn&#8217;t I just say they cannot be phished?&nbsp; Well, passkeys work in the sense that they are unphishable.&nbsp; But phishing sites can still phish for usernames and passwords.&nbsp; &nbsp;Passkeys do not stop bad people sending fake emails in order to steer users into fake websites that then steal usernames and passwords.</p><p>So what can they do with a stolen username / password?</p><p>Well,&nbsp; use them!&nbsp; Yes, the bad people can simply go to any PC not set up with a passkey for that website, and they will be prompted for username / password, and then perhaps some form of MFA. &nbsp;And, as we know, they can then break me!  </p><h4>The benefits of internet openness are eroded</h4><p>Remember that the internet and browsers give us openness and access from any point.&nbsp; &nbsp;If the problem above is solved by making passkeys obligatory (which is very difficult because you need to signon to set up a passkey), then you will be tied to specific devices for those services.&nbsp; So, if the service is a bank, you will not be able to check your balance from work or a friend&#8217;s PC &#8211; you will have to use your own devices with passkeys already setup.</p><h4>Passkeys are dangerous if you share devices!</h4><p>Whoa, surely passkeys don&#8217;t make things dangerous!&nbsp; Well, we are not sure yet, but they do open up some theoretical holes.&nbsp; For example, say a company has a loan PC and everyone knows the Microsoft Hello PIN.&nbsp; If a person saves a passkey on that PC, against the advice of the service provider, then it is seemingly useable by anyone who uses that PC.&nbsp;</p><p>Put another way, <strong>the Microsoft user becomes the actual user</strong>.&nbsp; If you know the PC&#8217;s PIN you have access to all passkeys and Microsoft provides a list of them all for you (see passkey administration above).&nbsp; That is a bit interesting to say the least.</p><h4>Giving control to Google, Microsoft, and Apple</h4><p>Like so many things in IT, the politics of control are rarely broached.&nbsp; The FIDO Alliance has many members including the big five IT companies and many of the major identity companies.&nbsp; FIDO has been promoting 2FA FIDO security keys since 2013.</p><p>Passkeys looks like a second attempt to solve the phishing problem, but are based upon using hardware in PCs and smartphones.&nbsp; This has appeal in finding a hardware-based solution without requiring a new piece of hardware.</p><p>But, and this is a very big but, while conceptually elegant, practically <strong>this puts the OS providers, Google, Microsoft, and Apple, smack in between users and their service providers</strong>.&nbsp; Your access to services is through your OS identity and your OS identity is controlled by your OS provider.&nbsp; I wonder if they will start charging for this service one day?  Maybe this is why they are cooperating at the moment?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nZHU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nZHU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nZHU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png" width="472" height="269.7142857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:472,&quot;bytes&quot;:1976768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nZHU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nZHU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fefb4ec-d802-4b6b-a5a6-b7246f8b4a89_1792x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Note that even though Apple&#8217;s passkey implementation will be different, they too will be in a controlling position.</p><h1>Passkeys are not the answer</h1><p>Passkeys are not a bed of roses!&nbsp; And passkeys are not the answer to Identity.</p><p>No doubt they are developing and will develop further, but in this early stage:</p><ul><li><p>passkeys only do authentication for on-line 2-party transactions</p></li><li><p>passkeys are an un-phishable authentication method that does not stop phishing</p></li><li><p>passkeys may limit the openness of the Internet</p></li><li><p>passkeys create a problem with shared devices</p></li><li><p>passkeys, if successful, put Google, Microsoft, and Apple even more in control than they are now</p></li></ul><p>One has to ask, &#8220;Is this the best we can do?&#8221;&nbsp; Passkeys look like a half-baked concept designed by a committee.&nbsp; Passkeys look like an attempt to rectify a previous failure, and are more like a bed of thorns than a bed of roses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JlYc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JlYc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JlYc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png" width="662" height="378.2857142857143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:662,&quot;bytes&quot;:2851899,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JlYc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 424w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 848w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!JlYc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd637a91f-c160-4c07-b54c-7eeab4d0bf06_1792x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[12. The Peculiar Case of Identity Digital Wallets]]></title><description><![CDATA[How Digital Wallets have evolved to the concept of Identity Digital Wallets and why this is somewhat peculiar.]]></description><link>https://www.newsletters.identity25.com/p/12-the-peculiar-case-of-identity</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/12-the-peculiar-case-of-identity</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Mon, 06 Nov 2023 21:52:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OjcN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OjcN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OjcN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OjcN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1581853,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OjcN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!OjcN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbfa7ba8-6ecc-414c-9c43-d5067ca78f95_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For Identity, 2023 is the year of Identity Digital Wallets, Verified Credentials, and Passkeys.&nbsp; These are all hot topics, important, and worthy of at least a newsletter each.&nbsp; In this newsletter I&#8217;ll consider Identity Digital Wallets &#8211; what they are and the inherent challenges in implementing them for Identity.</p><p>But why the title &#8220;The Peculiar Case of Identity Digital Wallets&#8221;?&nbsp; Well, because while they are a great idea, the very people promoting them have highlighted some massive implementation issues.&nbsp; That sounds peculiar to me!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Digital Wallet Functions</h1><p>Before I delve into <strong>Identity Digital Wallets (IDWs)</strong>, I&#8217;ll consider <strong>Digital Wallets (DWs)</strong>.&nbsp; DW is a general term that applies to many types of app.&nbsp; So categorizing them is not easy, but in this first attempt I&#8217;ll focus on the &nbsp;functions that DWs support.</p><p>The most obvious function is <strong>Card Support</strong>.&nbsp; Just like a wallet, the DW stores cards which can be then made digitally available.&nbsp; The Google Wallet and Apple Pay are the most well-known examples:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!71-1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!71-1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 424w, https://substackcdn.com/image/fetch/$s_!71-1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 848w, https://substackcdn.com/image/fetch/$s_!71-1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!71-1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!71-1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg" width="1006" height="465" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:465,&quot;width&quot;:1006,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!71-1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 424w, https://substackcdn.com/image/fetch/$s_!71-1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 848w, https://substackcdn.com/image/fetch/$s_!71-1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!71-1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffdd4911-d28d-4309-b9bf-a7a2981e1f5b_1006x465.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Note the card types supported are more than just payment cards.&nbsp; As per the Google example above, a Covid card, a transit card, and a membership card are all be supported.</p><p>Solutions that purely focus on storing <strong>identity cards</strong> in a wallet are <strong>EID</strong>s.&nbsp; The abbreviation EID (sometimes written eID) originally described identity cards which had a chip and hence were electronic.&nbsp; Now, in Identity, EID is used to describe the storing of such identity cards in a smartphone wallet.&nbsp; Current examples of EIDs are the initiatives in the USA to store drivers&#8217; licenses using Apple Pay.&nbsp;</p><p>I include within EIDs Identity Hubs such as Yoti, which have since 2014 utilised their own DW to build a user base and become an Identity Hub.&nbsp; But while they have gone beyond storing cards to storing other documents such as passports, they still function in a limited fashion.&nbsp; So, while they may claim to be full identity solutions (and IDWs as per my definition below), they are simply creating a digital version of physical IDs, thereby eliminating the need to carry all those plastic cards and documents.</p><p>One of the earliest and most successful wallet functions is the <strong>purse</strong>.&nbsp; Strange to think that a purse fits into a wallet, but some wallets do have pockets for coins, so I guess the analogy holds ok.&nbsp; Alipay and WeChat started as payments enablers by holding cash on the customers behalf.&nbsp;</p><p>And then we have the <strong>add-ons</strong>!&nbsp; I struggle to find a better word than this, but the challenge is that once you have a &#8216;killer function&#8217; to bring in the punters, such as a purse, you can then &#8216;add-on&#8217; all sorts of functions.&nbsp; Look at the main Alipay screen below:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0YVA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0YVA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 424w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 848w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 1272w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0YVA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png" width="329" height="332" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:332,&quot;width&quot;:329,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:158170,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0YVA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 424w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 848w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 1272w, https://substackcdn.com/image/fetch/$s_!0YVA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe4adad-bb99-4b2d-9526-3de6a73e3ab9_329x332.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>My expertise in Chinese script is very limited, but clearly there is a bit more functionality and interactivity going on than occurs in my physical wallet.&nbsp; There seem to be many financial and transport services that go beyond storing and presenting a simple card to actually executing transactions within the DW.</p><p>New Zealand has its own DW.&nbsp; <a href="https://www.dosh.nz/">Dosh</a> is an example that provides a purse and supports its own payment card.&nbsp; It is a relatively easy-to-use app that supports person to person payments and other general payment functions.&nbsp; But it is not yet ubiquitous &#8211; there is more to a DW than being good technology!</p><p>And, now, we have <strong>Identity</strong>.&nbsp; The Identity solutions proposed are a lot more than a card stored in an app &#8211; they are full ecosystems.&nbsp; I describe the approaches and what is happening in the next section.</p><p>So, in summary, DWs have many functions which I categorize as:</p><ul><li><p>card support</p></li><li><p>EID</p></li><li><p>purse</p></li><li><p>add-ons</p></li><li><p>identity</p></li></ul><p>They are relatively easy to build but need scale to be successful.&nbsp; The Chinese DWs, Alipay and WeChat, with user bases in the billions, show what success can be like.&nbsp; But, of course, reaching such lofty heights is not so easy!</p><h1>Identity Digital Wallets (IDWs)</h1><p>The concept of an Identity Digital Wallet (IDW) as a full Identity ecosystem has now emerged in the European Union (EU).&nbsp; This goes way beyond the concept of an EID DW.&nbsp; I&#8217;ll discuss the both initiative&#8217;s aims and the published issues with the security.</p><h3>EU eIDAS 2.0</h3><p>Initially, in 2014, the EU eIDAS (Electronic Identification, Authentication and Trust Services Regulation) focused on identification and authentication.&nbsp; Now, in its latest version, eIDAS 2.0 creates a regulatory framework for cross-border digital identity.&nbsp; A key part of this is the European <strong>Digital Identity Wallet</strong>, but in line with my &nbsp;terminology I&#8217;ll call this an IDW.&nbsp; The <strong>EU&#8217;s IDW</strong> aims to provide <strong>all the functions of Identity</strong> (the model below is from my <a href="https://www.newsletters.identity25.com/p/3-identity-fundamentals">newsletter 2</a>):</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YASA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YASA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!YASA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!YASA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!YASA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YASA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png" width="434" height="136.51923076923077" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c061ac67-8988-463e-b355-f638e601725e_2363x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:458,&quot;width&quot;:1456,&quot;resizeWidth&quot;:434,&quot;bytes&quot;:86161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YASA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!YASA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!YASA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!YASA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc061ac67-8988-463e-b355-f638e601725e_2363x743.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>As the EU states on their <a href="https://digital-strategy.ec.europa.eu/en/policies/eudi-wallet-toolbox">website</a>:</p><p><em>"The EU Digital Identity Wallet will provide a secure and convenient way for European citizens and business to share identity data needed for accessing digital services such as checking in at the airport, renting a car, opening a bank account, or when logging in to their accounts on large online platforms. &nbsp;With a click of a button on their phone they will be able to securely share information stored in digital versions of their driving licence, professional or educational credentials, and medical prescriptions."</em></p><p>Clearly the EU IDW aims to support 2-party and 3-party identity transactions in multiple environments of in-person and on-line, for multiple types of transactions, and in multiple countries.&nbsp; This is a hugely ambitious project!</p><p>Being the EU, this initiative requires a pilot.&nbsp; The EU, being the EU, has four pilots being run by <a href="https://digital-strategy.ec.europa.eu/en/policies/eudi-wallet-implementation">four huge consortia with a cast of thousands</a>.&nbsp; I suppose the rationale is that one of the consortia must be successful, but it is hard not to be a little sceptical about their chances (check out the long lists of participants and the pilots are schedule to be running in 2025).</p><h3>The little issue of security</h3><p>So there are large expectations for this IDW and much activity.&nbsp; But the EU&#8217;s own documentation highlights a security issue that is both conceptually and practically impossible to resolve!</p><p>In the EU&#8217;s design document, &#8220;The Common Union Toolbox for a Coordinated Approach Towards a European Digital Identity Framework, The European Digital Identity Wallet Architecture and Reference Framework, January 2023 Version 1.0.0.&#8221;, pages 28-29, it states:</p><p><em>&#8220;Where an EUDI Wallet Solution has an application running on a mobile device, there may be a need for additional trusted components which are not part of that application but are nevertheless part of the EUDI Wallet.&nbsp; Such a need may arise for reasons:</em></p><ul><li><p><em>Security: e.g., if a particular device does not have sufficiently secure hardware like a secure element, external hardware components like smartcards may be needed&#8221;</em></p></li></ul><p>In other words, the EU IDW will be secured through hardware and this may be an external device.&nbsp; How are we going to make that work?&nbsp; Does anyone in the EU understand the impossibility of the EU population all having homogeneous smartphone security hardware?&nbsp; It is problematic getting two smartphones from the same manufacturer to operate the same but, if we want a ubiquitous IDW solution for all citizens, we will need all smartphones in use, from different manufacturers with multiple models and versions, to somehow operate the same way!</p><p>We tried this strategy in New Zealand in a SEMBLE, an initiative to create a payments card DW.&nbsp; The complexity of using the security hardware in current smartphones from just one manufacturer was highly problematic and the project failed &nbsp;(<a href="https://www.stuff.co.nz/business/82147557/developers-of-semble-mobile-wallet-app-refocusing">https://www.stuff.co.nz/business/82147557/developers-of-semble-mobile-wallet-app-refocusing</a>).&nbsp; Think of doing this for all smartphone manufacturers and all common smartphone models still being used!</p><p>Well, one EU body recognizes the problem.&nbsp; The European Union Agency for Cybersecurity (ENISA) is the &#8220;Union&#8217;s agency dedicated to achieving a high common level of cybersecurity across Europe&#8221;.&nbsp; In their <a href="https://www.enisa.europa.eu/publications/digital-identity-standards">report</a> &#8220;Digital Identity Standards, Analysis of standardisation requirements in support of cybersecurity policy, July 2023&#8221; they consider standards in the light of eIDAS 2.0 and come up with several recommendations, including (my bolding):</p><p><em>&#8220;In the context of the EU Digital Identity Wallet, EU policymakers should make use of the new Digital Markets Act to provide direct access from the Mobile Application to the security anchor provided by EU CC certified secure elements available on smartphones. This direct assessment will help create a Trusted Mobile EU Digital Identity. This recommendation should be complemented by a new standardisation request to the European Standardisation Organisations, to <strong>develop a unique API from the mobile application to the security anchor</strong> provided by the secure element certified by the EU cybersecurity certification scheme. <strong>This is crucial for the provision of full interoperability by various smartphone manufacturers</strong>.&#8221;</em></p><p>So, ENISA recommends that we need a common security API for ALL smartphones.&nbsp; This recognizes the need for a common way of accessing some standard security technology.&nbsp; But that does not solve the problem.&nbsp; <strong>There is no magic wand to turn a technology base of thousands of different devices into a standards-based environment.</strong></p><h3>Summary</h3><p>So I have described Digital Wallets (DWs) and Identity Digital Wallets (IDWs).</p><p>The wallets that concern Identity are EID DWs and IDWs.&nbsp; EID DWs, such as a drivers license stored in a wallet, have utility but limited functionality.&nbsp; IDWs, if successful, will be the most significant Identity ecosystems on the planet even surpassing passports.</p><p><strong>But while EU IDW project has a huge amount of participation it seems most peculiar in that it has already identified major challenges without having any inkling of how to solve the security challenge in practice.</strong></p><p>Maybe, just maybe, the reason we do not yet have a fully functioning IDW is because it is almost impossible to make it a reality.&nbsp; Maybe, just maybe, trying to legislate an IDW into existence is more about keeping the good news story going rather than being a well thought out strategy.&nbsp; Maybe, just maybe, we need to think this through a bit more.</p><p>All the best,</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Newsletter 6B - Identity Verification, Big Tech Identity and Gartner]]></title><description><![CDATA[A refresh of market segments based on Gartner 2023 Identity Verification report]]></description><link>https://www.newsletters.identity25.com/p/newsletter-6b-identity-verification</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/newsletter-6b-identity-verification</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Fri, 27 Oct 2023 05:00:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8n4M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8n4M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8n4M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8n4M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:431717,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8n4M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!8n4M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54f80560-c320-4799-8bf6-58cdcec1aeae_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Hi trendsetters,</p><p>This newsletter</p><ul><li><p>updates some key market segment terminology and</p></li><li><p>suggests a Gartner report to read.</p></li></ul><h2>Identity Verification and Big Tech Identity</h2><p>The main terminology that I want to change is the market segment that I previously called KYC (Know Your Customer).&nbsp; This market segment uses a number of techniques, such as identity proofing and biometric matching, to verify the identity of a person to a new third party such as a lawyer, accountant, or real estate agent.&nbsp; It has huge volume worldwide and is probably one of the few market segments making any money!</p><p>But, as Gartner&#8217;s insightful 2023 report rightly points out:</p><ul><li><p>KYC is an ongoing process that is greater than a single identity verification transaction as institutions need to monitor the status of identities over time,</p></li><li><p>The need to verify identity is more than just KYC and this need is increasing as organizations want to be sure who their customer really is.</p></li></ul><p>Besides these useful observations, Gartner also changed their naming of the segment from &#8216;Identity Proofing and Affirmation&#8217; to &#8211; wait for it &#8211; &#8216;Identity Verification&#8217;.&nbsp; I love it &#8211; it actually states what the process does.&nbsp; &nbsp;And so I have updated my Newsletter 6 &#8211; Market Segments&#8217; diagram accordingly:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uq7c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uq7c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 424w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 848w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 1272w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uq7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png" width="912" height="318" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:318,&quot;width&quot;:912,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:90032,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uq7c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 424w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 848w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 1272w, https://substackcdn.com/image/fetch/$s_!uq7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0a0870-fd6c-43d7-aea5-9e2e23e5d59b_912x318.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You will note that I have also:</p><ol><li><p>Changed &#8216;Social Media Identity&#8217; to &#8216;Big Tech Identity&#8217;.&nbsp; Why?&nbsp; Well, the federated identity options that Meta, Google, and Apple previously provided to support social media level security are being supplanted by the passkey initiative that aims to deliver better security and ease of use.&nbsp; How this plays out will be a subject of a future newsletter, but the with Microsoft, Apple, and Google leading this passkey initiative, Big Tech may well play a major part in the future of Identity.</p></li><li><p>Reordered the segments on the left (in the blue shading) to allow me to highlight the segments where we find the most commercial activity not dominated by Big Tech, and I have provided a list of the major international companies in this space:</p></li></ol><h5>Identity and Access Management</h5><ul><li><p>Okta</p></li><li><p>Thoma Bravo&#8217;s Ping, ForgeRock, and SailPoint</p></li></ul><h5>Identity Verification</h5><ul><li><p>Jumio (USA)</p></li><li><p>Mitek (USA)</p></li><li><p>LexisNexis Risk Solutions (USA)</p></li><li><p>Trulioo (Canada)</p></li><li><p>Onfido (UK)</p></li><li><p>GB Group (UK)</p></li><li><p>IDnow (Germany)</p></li><li><p>IDEMIA (France)</p></li><li><p>Sumsub (Cyprus)</p></li></ul><h5>Identity Hubs</h5><ul><li><p>ID.me (USA)</p></li><li><p>Yoti (UK)</p></li><li><p>Digi.me (UK)</p></li></ul><p>I also want to highlight that Identity Hubs have taken the seemingly obvious step of remembering an identity that they have verified and reusing it.&nbsp; Hence, they could be considered to be Identity Verification companies, but my reading is that they have changed their strategies and no longer focus on providing Identity Verification services.&nbsp;</p><h2>2023 Gartner Report</h2><p>I do recommend the Gartner paper which is available through many companies that are named in the report, including <a href="https://go.jumio.com/gartner-market-guide-2023">Jumio</a>.&nbsp; It is a lot easier to read than the 2022 report that has a huge amount of detail and a veritable cure for insomnia if you choose to go <a href="https://content.ekata.com/rp-form-0522gartnermarketguide.html">there</a>.</p><p>The report suggest that the Identity Verification market will decrease as Digital Wallet solutions come online!&nbsp; That bucks the trend of every other report that I have read that suggests continuous growth.&nbsp; Maybe, just maybe, some realism is creeping in!</p><p>All the best and watch out for my upcoming Digital Wallet newsletter.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[11. Identity Ecosystems]]></title><description><![CDATA[What are ecosystems and are they important?]]></description><link>https://www.newsletters.identity25.com/p/11-identity-ecosystems</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/11-identity-ecosystems</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sat, 09 Sep 2023 21:00:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!suDQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!suDQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!suDQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!suDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1733416,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!suDQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 424w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 848w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!suDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac44eeab-4a05-4ddf-8ae9-ea321aba186f_1980x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The New Zealand Department of Internal Affairs recently stated that it is contributing to a &#8220;Future State New Zealand <strong>Identity Ecosystem</strong>&#8221; (my bolding, DIA discussion paper, June 2023).</p><p>The establishment of a national identity ecosystem is an important subject.&nbsp; What is an identity ecosystem?&nbsp; I ask what should we be aiming for as a society?  And is it one or multiple identity ecosystems?&nbsp;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h3>What is an Identity Ecosystem?</h3><p>Defining the term <strong>&#8216;ecosystem&#8217;</strong> is a useful starting point.&nbsp; Wikipedia states:</p><p><em>An ecosystem (or ecological system) consists of all the organisms and the physical environment with which they interact.&#8202; These biotic and abiotic components are linked together through nutrient cycles and energy flows. Energy enters the system through photosynthesis and is incorporated into plant tissue. By feeding on plants and on one another, animals play an important role in the movement of matter and energy through the system.</em></p><p>Wikipedia describes a &#8216;<strong>biological ecosystem&#8217;</strong> that has evolved to a steady state.&nbsp; Such a biological ecosystem has systemic features of many co-existing parts that, in a sense, cooperate.&nbsp; An &#8216;<strong>identity ecosystem&#8217;</strong> will share this systemic feature - it too will have many cooperating parts.</p><p>But an identity ecosystem is <strong>designed by humans</strong>.&nbsp; This additional dimension is obviously important &#8211; it determines everything!&nbsp; Such as whether the thing works, how efficient it is, how secure it is, and how much it costs!</p><p>So, we must avoid being too romantic about identity ecosystems - they are not natural, they are not easy, and there is no preordained &#8216;order of things&#8217; to define how they should work.</p><h3>Identity Ecosystems Attributes</h3><p>So, there are different types of ecosystems.&nbsp; To understand these differences, I categorize identity ecosystems using three attributes:</p><ol><li><p>the operational environments that are supported</p></li><li><p>the type of transactions that are supported (2-party and/or 3-party)</p></li><li><p>the level of security</p></li></ol><p>1-2 have been described in previous newsletters.</p><p>The third, the level of security, is determined by what identity-based transactions are being supported.&nbsp; If the transaction is high value or high risk, like obtaining a passport, a high level of security should be expected.&nbsp; If the transaction is low value or low risk, such as accessing social media, a lower level of security may be appropriate.</p><p>Together, these three attributes define the <strong>scope of an identity ecosystem</strong>.&nbsp; There are two classifications:</p><ul><li><p>a <strong>broad-scope identity ecosystem</strong> that supports multiple variations of environment, transaction type, and security level</p></li><li><p>a <strong>narrow-scope identity ecosystem</strong> that supports limited environments, transaction types, and levels of security.</p></li></ul><h3>Loosely and Tightly Coupled Ecosystems</h3><p>An additional aspect that is important for ecosystems is how the ecosystem functions.&nbsp; To describe this, I will focus on how tightly the entities within the ecosystem are coupled together.</p><p>One extreme features <strong>loosely coupled</strong> ecosystems with lots of independent entities that can randomly interact with each other.&nbsp; They do not have hard and fast connections.&nbsp; Biological ecosystems are clearly loosely coupled with a huge variety of entities and multitudinous interactions.&nbsp; These many-to-many relationships somehow work, primarily because millennia of evolution have produced a steady state system.</p><p>At the other extreme, <strong>tightly coupled</strong> ecosystems have a structure, and the entities interact according to patterns that some might characterize as rules.&nbsp; Such ecosystems are much more likely to be made by humans.</p><h3>Current and Future Identity Ecosystems</h3><p>I use the three attributes and degree of coupling described above to analyze a series of current and developing identity ecosystems.</p><h4>Government Identity Documents</h4><p>I start where we all started &#8211; birth certificates, driver&#8217;s licenses etc.&nbsp; &nbsp;They are useful in many environments and transaction types, so they have broad scope, but they have limited security.&nbsp; They are loosely coupled ecosystems.</p><h4>International Passports</h4><p>Passports are clearly the biggest identity solution on the planet.&nbsp; They are highly effective in border locations where hardware is installed, although they can be used elsewhere for general identity in a moderately coupled manner.</p><h4>National Identity Solutions</h4><p>The most sophisticated and well-known national Identity solutions are in the Scandinavian countries and Estonia.&nbsp; BankID operates in Sweden and Norway.&nbsp; It evolved from a smart-card based solution to being predominantly based on smartphones providing 2nd Factor Authentication.&nbsp; It focuses on on-line use and can be used with both government services and commercial services in a tight configuration.&nbsp;</p><h4>National Hybrid Identity Card / Biometrics Solutions</h4><p>These are an emerging type of solution similar to National Identity Solutions.&nbsp; For example, the Philippines is introducing a chip-based identity card and collecting iris and fingerprint biometrics at the same time.&nbsp; If well implemented, this will give all sorts of options in the future and shows how countries with minimal Identity infrastructure may be able to take a major leap to a sophisticated technology approach.&nbsp; They are likely to be tightly coupled.</p><h4>Social Media Identity</h4><p>Federated Identity is quite important for many of the four billion social media users!&nbsp; Based around protocols, such as OAuth, OpenID, and OpenID Connect, this is an on-line 2-party solution, with a large unverified user base, that operates tightly.&nbsp; It is difficult to measure the security, but the absence of any major reports of disaster suggests that the technologies themselves are secure.</p><h4>Big Tech Passkeys</h4><p>I&#8217;ll cover this in a future newsletter, but the tech giants Google, Microsoft, and Apple along with FIDO, on 20 May 2023, announced the technology of passkeys as the new identity solution. &nbsp;Passkeys could be seen as an evolution of FIDO 2nd Factor Authentication, but it is much more than that.&nbsp; Centralized management of passkeys to remove the reliance on passwords (and hence minimize the risk of phishing attacks) has a lot of positives and a few negatives (do we trust them?).&nbsp; Passkeys, if and when it achieves some sustainable volume, will have an on-line, 2-party focus in a tight configuration.</p><h4>Identity Ecosystem Summary</h4><p>The ecosystems analysed above are:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Kkf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Kkf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Kkf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg" width="792" height="565" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:565,&quot;width&quot;:792,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Kkf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0Kkf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3799497f-cb30-4d70-99da-babced72a972_792x565.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There are some trends in this analysis:</p><ul><li><p><strong>we do not have any identity ecosystems that are both broad-scope and highly secure</strong> - government identity documents is the only identity ecosystem that covers all environments and transaction types (i.e. is broad) and it is not secure.&nbsp; I know of no other broad-scope identity ecosystems.</p></li><li><p><strong>current secure identity ecosystems are tightly coupled</strong> - this borders on stating the obvious, but governmental, commercial and big tech development build on the technology stacks we currently have, and utilize real-time communication and strongly-typed messaging.&nbsp; That is, Identity providers utilize current technologies to tightly couple entities and to thereby gain security.</p></li></ul><h3>Conclusion / Observations</h3><p>I will to conclude with these points:</p><ol><li><p><strong>the ecosystem approach is useful</strong> - the discussion in this newsletter is worthwhile.&nbsp; We need to have a way of discussing identity at a national level, and the concept of ecosystems allows this discussion to take place.&nbsp; By that, I mean at a national level, we must go beyond simply discussing standards, legal accreditation, and technologies.</p></li><li><p><strong>identity ecosystems are a good idea</strong> - I started by recounting how Department of Internal Affairs&#8217; aim to contribute to a &#8220;Future State New Zealand Identity Ecosystem&#8221; and asking whether this is a good goal.&nbsp; While I have not focused on proving that in this newsletter, it seems intuitively obvious that ecosystem solutions at the same level as Payments solutions would be beneficial.</p></li><li><p><strong>a secure broad-scope identity ecosystem is not easy</strong> &#8211; history supports this.&nbsp; I think there are two primary reasons for slow progress: 1) it is a very difficult problem, and 2) industry is waiting on government.&nbsp; Unfortunately, it is not the role of government to fix everything, so industry needs to find its own ways to move forward.</p></li><li><p><strong>narrow-scope identity ecosystems will develop initially</strong> &#8211; before the big solution arrives, we will have narrow-scope identity ecosystems for industries, social groups, and communities.&nbsp; This may be the future for the next 5-10 years or more.</p></li></ol><p>So, Identity has some things to do.&nbsp; In the next few newsletters, I&#8216;ll consider how to design an identity ecosystem and discuss some current approaches to developing identity solutions.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[10. The Reasonable Future: Identity 2.5]]></title><description><![CDATA[Where I believe the Identity must go.]]></description><link>https://www.newsletters.identity25.com/p/10-the-reasonable-future-identity</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/10-the-reasonable-future-identity</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Sun, 30 Jul 2023 02:07:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7NE9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7NE9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7NE9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7NE9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2021582,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7NE9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!7NE9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1875ca66-0aa8-4d9c-bc94-83153b4e272d_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The title of this newsletter is deliberate &#8211; Identity 2.5 is reasonable: that is, there is a coherent argument for Identity 2.5.&nbsp; It is not about ideology nor is it about opinion.&nbsp; Sure, the views expressed are based on my knowledge, but when determining the future of Identity I present a reasoned argument and I ask you to focus on the reasoning for my approach.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.newsletters.identity25.com/subscribe?"><span>Subscribe now</span></a></p><p>A quick recap.&nbsp; I define three current paradigms:</p><ul><li><p>Identity 2 Technology &#8211; our current disaster of multiple methods, fraud, and poor customer service</p></li><li><p>Identity 2.5 Networked &#8211; a networked approach that uses current technologies in useful ways</p></li><li><p>Identity 3 Decentralization &#8211; a future where identities exist under the control of the customer.</p></li></ul><h2>My Reasoning Summarized</h2><ul><li><p>Identity 2 Technology should not be allowed to continue</p></li><li><p>Identity 3 Decentralized is decades away and we can&#8217;t afford to wait for it</p></li><li><p>Identity 2.5 Networking is demonstratable today and it works.</p></li></ul><p>Given these reasons, Identity 2.5 is our immediate future.</p><h2>Identity 2 Technology</h2><p>The status quo is Identity 2 Technology, our current chaotic Identity world.&nbsp; In this paradigm:</p><ul><li><p>we add security through complexity resulting in a horrid customer experience</p></li><li><p>we cannot support in-person Identity (anyone remember the highly insecure Covid passport?)</p></li><li><p>on-line fraud is prevalent.</p></li></ul><p>As I have covered the topic in-depth in previous newsletters, I will not go on about these current performance issues here.&nbsp; Suffice to say that we should not accept this state of affairs.</p><h2>Identity 3 Decentralization</h2><p>The promised nirvana, Identity 3 Decentralization, cannot be achieved in our current ICT environment, and the industry knows it, even if it will not admit it!</p><p>That is quite a statement!&nbsp; There are millions, if not billions, of dollars being invested in decentralization.&nbsp; Fortunes are being made and, if I am right, fortunes will be lost through a failed attempt to implement decentralized Identity (although not necessarily by the same people, unfortunately).</p><p>I present three reasons why Decentralization will not deliver an Identity solution now:</p><ol><li><p>Decentralization runs on personal digit devices (PDDs) that are inherently insecure</p></li><li><p>Decentralization has failed to deliver the intended Decentralized Identifiers (DIDs)</p></li><li><p>Decentralization has changed focus to Verified Credentials (VCs).</p></li></ol><h4>Insecure Personal Digital Devices (PDDs)</h4><p>Identity 3 Decentralization is based, of course, on not holding central information.&nbsp; In its most fervent forms, it castigates the wicked central masters and exploiters of personal information, and longs for a world where the individual is the sovereign of their own realm.&nbsp; But the data must go somewhere, and that is on personal digital devices.</p><p>Now, the first law of ICT security should be &#8220;Personal digital devices are inherently insecure&#8221;.&nbsp; Decades of viruses, Trojan horses, and fraud surely make this clear.&nbsp; That PC and that smartphone are not highly secure devices.&nbsp; The security of PDDs is average at best.</p><p>And we should not be surprised &#8211; PDDs are designed to be &#8216;open&#8217;!&nbsp; That is, the movements for open systems, open platforms, and open-source code have delivered great functionality where multiple software components can interact in the same environment.&nbsp; A corollary to this is, of course, that it is much easier for malicious software to be effective. &nbsp;And it is, and so PDDs are insecure.</p><p>This means that we will not have a society using secure PDDs for many decades to come.&nbsp; Even if all new PDDs magically became secure, the time it would take to roll over all PDDs is decades.&nbsp; So practically, any Identity solution has to work with a world of insecure PDDs.</p><p>See the problem?&nbsp; Pragmatically, Decentralization cannot be secure, and is quite a problem for something that promises a universal solution to Identity!&nbsp; Decentralization has a very large problem of operating within insecure PDDs and it has no solution!</p><h4>Decentralization has failed to deliver Decentralized Identifiers (DIDs)</h4><p>DIDs are the fundamental building blocks for Decentralization but the functionality that was envisaged does not exist in practice .&nbsp; W3C has delivered a technical specification of a DID, and no matter what specifications have been published, DIDs have not been delivered.</p><p>A good place to start is the W3C Credentials Community Group&#8217;s <em>Use Cases for Decentralized Identifiers</em>.&nbsp; One of the example use cases is:</p><p><em>When Sally earned her master&#8217;s degree at Oxford, she received a digital diploma which contained a decentralized identifier she provided. Over time, she updates the cryptographic material associated with that DID to use her latest hardware wallet, with biometric protections and a quantum resistant algorithm. A decade after graduation, she applies for a job in Japan, for which she provides her digital diploma by uploading it to the prospective employee&#8217;s website. To verify she is the actual recipient of that degree, she uses the decentralized identifier to authenticate, using her current hardware wallet (with rotated keys). In addition to the fact that her name matches the name on the diploma, the cryptographic authentication provides a robust verification of her claim, allowing the employer to rely on Sally&#8217;s assertion that she earned a master&#8217;s degree from Oxford.</em></p><p>This excerpt clearly shows what was envisaged for DIDs &#8211; it replaces a central identity provider with a decentralized identity!&nbsp; This is made explicit in a diagrammatic representation of a DID&#8217;s functionality (note the &#8216;deleted&#8217; Identity Provider on the right):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!adR_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!adR_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 424w, https://substackcdn.com/image/fetch/$s_!adR_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 848w, https://substackcdn.com/image/fetch/$s_!adR_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 1272w, https://substackcdn.com/image/fetch/$s_!adR_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!adR_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png" width="602" height="608" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fba3f576-91d6-4ea1-be10-a597882edc44_602x608.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91554,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!adR_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 424w, https://substackcdn.com/image/fetch/$s_!adR_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 848w, https://substackcdn.com/image/fetch/$s_!adR_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 1272w, https://substackcdn.com/image/fetch/$s_!adR_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffba3f576-91d6-4ea1-be10-a597882edc44_602x608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Looks great, but has anyone seem a prototype yet?&nbsp; The answer is no &#8211; all we have is a published specification.&nbsp;</p><p>I contend that for Decentralization, DIDs are at the centre of its Identity strategy and it has failed to deliver DIDs because DIDs cannot be delivered in today&#8217;s ICT environment.</p><h4>Decentralization has changed focus to Verified Credentials</h4><p>Now tech startups are innovators and, when you are stuck, one of the best possible innovations is to change the game.&nbsp; So, now Verified Credentials (VCs) have now been ushered into the limelight. VCs, if implemented correctly, will be secure.&nbsp; But they will not be an Identity solution as they do not do Identification and Authentication.&nbsp; Remember the basic processes of Identity:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NomT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NomT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!NomT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!NomT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!NomT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NomT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png" width="458" height="144.0686813186813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:458,&quot;width&quot;:1456,&quot;resizeWidth&quot;:458,&quot;bytes&quot;:86161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NomT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 424w, https://substackcdn.com/image/fetch/$s_!NomT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 848w, https://substackcdn.com/image/fetch/$s_!NomT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 1272w, https://substackcdn.com/image/fetch/$s_!NomT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1d62341-fee0-4d71-a37e-d1b3f55ca830_2363x743.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>VCs sit on the right-hand side &#8211; a technique for Data Sharing.&nbsp; The debate about whether they are a good technique has yet to occur, but suffice to say that Data Sharing alone is not an Identity solution.&nbsp; And VCs will likely have other issues which I&#8217;ll cover in a future newsletter.</p><p>Decentralization, or should I say those commercial entities promoting decentralization, have switched from Identity to managing credentials.&nbsp; They realise that Identity cannot be decentralized in our current environment and so head off to find better pastures!</p><h4>Decentralized summarized</h4><p>Decentralization operates on PDDs.&nbsp; PDDs are inherently insecure so Decentralization cannot be secure which is cataclysmic for an Identity solution.&nbsp; This problem is confirmed by Decentralization&#8217;s failure to deliver DIDs.&nbsp; The resolution of this issue has been to change focus to Verified Credentials.&nbsp; While VCs have capabilities, they are not general Identity solutions.&nbsp; Decentralization has failed to deliver Identity and has given up the quest to do so.</p><h2>Identity 2.5 Networked</h2><p>Why do I believe that Identity 2.5 Networked will work?&nbsp; Well, because it does!&nbsp; Most countries are in Identity 2, whereas the Nordic countries have moved to Identity 2.5.</p><p>Now, the standard rejection of that argument is that it only works because the Nordic countries have a national personal number. &nbsp;This is not a good argument.&nbsp; We know that we have perfectly good tokenization techniques that link databases together, so there is no inherent reason that networked solutions are not possible.&nbsp; That networked solutions are easier in Nordic countries is simply an advantage for them.</p><p>As the title of my newsletter indicates, I am an advocate for Identity 2.5 Networked.&nbsp; Besides advocacy, I have also created my own solution called General Identity Protocol.&nbsp; I discuss this further in future newsletters.</p><h2>Summary</h2><p>Some of the world is hell-bent of achieving Identity 3 Decentralization and, ironically, this is not going to happen anytime soon.&nbsp; With our current proven technologies we have all the building blocks to build sophisticated Identity solutions that provide a good customer experience and good security.&nbsp; That is where we should be spending our time, rather than dreaming of an impossible future.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[9. Identity in a Nutshell]]></title><description><![CDATA[A short and sweet summary of Identity.]]></description><link>https://www.newsletters.identity25.com/p/cleaning-up-and-moving-on</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/cleaning-up-and-moving-on</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 20 Jul 2023 08:18:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uUiY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uUiY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uUiY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uUiY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:791366,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uUiY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!uUiY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ebf0c7a-2ff4-4b94-8aaf-93c41cd23df9_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This newsletter brings all the previous newsletters together in one place &#8211; Identity in a nutshell, so to speak.&nbsp; I think it appropriate to summarize the basics of Identity before, in following newsletters, going more in-depth, critiquing different approaches, and suggesting what the future will look like.</p><p>So here it is &#8211; Identity as well as I know it; based on my experience and documented in my previous eight newsletters.&nbsp; The process of summarizing these eight newsletters suggested some revisions and these have been made to this summary edition.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.newsletters.identity25.com/subscribe?"><span>Subscribe now</span></a></p><h3>Identity is important for Society</h3><p>The starting point is Identity&#8217;s importance for society.&nbsp; Consider the list of activities and entities below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hvq-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hvq-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hvq-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg" width="1092" height="383" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:383,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66659,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!hvq-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hvq-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf270e90-03a4-4ca8-adaa-f9e3ab3cc11e_1092x383.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Clearly, a number of the activities involve identifying ourselves, and many of our relationships with the entities shown are based on identity.&nbsp; We identify ourselves regularly in many situations that require security, and we want such services to be easy-to-use&nbsp;and convenient.&nbsp; Identity is not a nice-to-have &#8211; it is part of the very fabric of our society and our legal system.&nbsp; Identity is important!</p><h3>Identity-based Transactions</h3><p>I use the term transaction in an everyday manner &#8220;to carry on or conduct business&#8230; to a conclusion&#8221;.&nbsp; That is, a transaction is a sequence of actions with a specific form and time period. Of course, not all transactions involve identity as shown in the picture below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1NiN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1NiN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 424w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 848w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 1272w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1NiN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png" width="583" height="426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:583,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34220,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!1NiN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 424w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 848w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 1272w, https://substackcdn.com/image/fetch/$s_!1NiN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f9858aa-4d00-4827-bf12-5b2a724b47c5_583x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Transactions split into anonymous transactions and identity-based transactions. &nbsp;Examples of anonymous transactions are buying a ticket for a movie or buying an ice cream.&nbsp; At no time are you identified and you are anonymous (this is not to say that you cannot be traced, but that is another story&#8230;).</p><p>These newsletters are all about the identity-based transactions (in the red circle above).&nbsp; In these transactions, the person&#8217;s identity is important.&nbsp; These transactions are for a specific individual.</p><p>I differentiate identity-based transactions into named and nameless.&nbsp; Most transactions are named, meaning that the recipient of the information wants to know who you are &#8211; they want to know your name.&nbsp; In the alternative, nameless transactions, the recipient does not know your name.&nbsp; This is how a covid-passport should operate &#8211; the recipient knows you are covid-free but does not know your name &#8211; you are nameless.&nbsp;</p><h3>Identity Processes</h3><p>There are two basic identity processes that occur within identity-based transactions.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9lPL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9lPL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 424w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 848w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 1272w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9lPL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png" width="546" height="183" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:183,&quot;width&quot;:546,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22013,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!9lPL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 424w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 848w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 1272w, https://substackcdn.com/image/fetch/$s_!9lPL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2952af54-bddc-41a7-baa7-37ea12dcf917_546x183.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The first process, identification and authentication, is obvious and very important.&nbsp; An identity-based transaction needs an identification and authentication process appropriate to the risk of the transaction.&nbsp; Buying a house needs more security than taking a book out of the library. Identification and authentication is the hard, stressful bit, hence the red colour.</p><p>And every transaction has a purpose beyond identification and authentication, and this purpose is achieved either through the use of some personal data or the sharing of personal data.&nbsp; An example of use of data is checking that a person has the required permission for entry, while an example of data sharing is opening a new account.&nbsp; This is more about growth, hence the green colour.</p><p>Both processes are important.&nbsp; Without appropriate identification and authentication, fraud can occur.&nbsp; Without data use or data sharing the transaction cannot achieve its purpose.&nbsp;</p><h3>The &#8216;Real Context&#8217;: Parties and Environments</h3><p>I write &#8216;real context&#8217;, because the number of parties and the environment are where Identity &#8216;really happens&#8217;.&nbsp;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VgFU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VgFU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 424w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 848w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 1272w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VgFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png" width="1315" height="774" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1315,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:259988,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!VgFU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 424w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 848w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 1272w, https://substackcdn.com/image/fetch/$s_!VgFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8af96c06-e7f0-4e9b-aab6-23bd94ac670b_1315x774.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The diagram above shows the inescapable two dimensions of Identity: the parties who are involved, and the place where they transact.&nbsp; They are inescapable because this is how our world is organized.</p><p>For parties, there are 2-party and 3-party identity-based transactions.&nbsp; 2-party transactions are simply a person and an organization, while 3-party transactions involve a person, an organization that knows the person, and an organization that does not know the person.&nbsp; 3-party is the difficult situation of proving to someone, who has never met you, that you are who you claim to be.</p><p>The places are the obvious ones: the physical environment, communicating on the telephone, and the on-line world.&nbsp; While these are obvious, each environment has quite different communication possibilities and, when combined with both 2-party and 3-party transactions, there is a lot of variety and complexity.</p><p>So, parties and place are the real context of Identity, and it is not a simple context.</p><h3>Identity Performance</h3><p>Given the context above, how well does Identity do?&nbsp; Well, it&#8217;s not great.&nbsp; In the diagram below, performance is shown using traffic light colours: green = good, orange = ok, red = bad.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kzlE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kzlE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 424w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 848w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 1272w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kzlE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png" width="910" height="539" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:539,&quot;width&quot;:910,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117285,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!kzlE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 424w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 848w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 1272w, https://substackcdn.com/image/fetch/$s_!kzlE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0a1e972-10ab-41d7-9ca1-5879f9db85df_910x539.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The judgements above are mine.&nbsp; I find that the only redeeming feature of identity is the availability of 2-party solutions.&nbsp; If I think about ease of use for 2-party transactions, I find cards in a physical environment mostly good, answering 20 questions to identify myself on the telephone as painful, and the online experience as being excruciating, with check codes and the like varying service by service and, it seems, by the time of the day! &nbsp;3-party ease of use is worse, and security and cost just do not look good anywhere.</p><p>Identity is not easy to use, Identity is not secure, and Identity is not cheap.&nbsp; This is not good news.</p><h3>Current Status of Markets and Technologies</h3><p>So what is behind and in front of all this poor performance?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HCfk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HCfk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 424w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 848w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 1272w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HCfk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png" width="942" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8401549b-5e69-42d4-9762-5aca79454364_942x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:942,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169901,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HCfk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 424w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 848w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 1272w, https://substackcdn.com/image/fetch/$s_!HCfk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8401549b-5e69-42d4-9762-5aca79454364_942x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Well, we have established market segments of Identity (the top half of the above diagram), but these are somewhat eclectic having evolved in a series of near accidents.&nbsp; For example, Know Your Customer only exists because of Anti-Money Laundering / Countering the Financing of Terrorism&nbsp;legislation.&nbsp; These segments do not share common origins or common strengths, but do share common problems.</p><p>Notwithstanding the eclectic nature of the market, there are several enabling and developing Identity technologies that have strengths and potentials (the bottom part of the diagram above).&nbsp; Not of all these will be successful, but one cannot doubt the power of such technologies as biometrics.&nbsp; But, so far, they have not delivered a significant change in the performance of Identity.&nbsp;</p><h3>Identity Paradigms</h3><p>It is relatively clear that Identity is used widely and is important, that Identity has a complex context, that Identity has performance issues, that the market is underdeveloped, and that many enabling and developing technologies are trying to solve the problem.</p><p>But to take the conversation forward, I need to both generalize and conceptualize.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wp-t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wp-t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 424w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 848w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 1272w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wp-t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png" width="939" height="503" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22919a9a-9fe5-4827-9067-6a766264e358_939x503.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:503,&quot;width&quot;:939,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86085,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Wp-t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 424w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 848w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 1272w, https://substackcdn.com/image/fetch/$s_!Wp-t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22919a9a-9fe5-4827-9067-6a766264e358_939x503.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>My approach to conceptualizing Identity is the series of paradigms above.&nbsp; Briefly, &#8220;knowledge&#8221; is simply knowing a secret, &#8220;documentation&#8221; is having some proof of identity, &#8220;technology&#8221; is our current malaise, &#8220;networking&#8221; utilizes the power of current identity hubs and current communications, and &#8220;decentralization&#8221; is an envisaged future technology-based Identity.</p><p>These paradigms do not occur in a strict sequence and they vary by country, industry and organization.&nbsp; But they have evolved over time, so in a sense the world is adding more paradigms as it moves from left to right in the diagram above.</p><p>I see most of the planet firmly located in Identity 2 Technology.&nbsp; We have been here a while and we do not seem to be moving anywhere fast.&nbsp; Technology has &#8216;improved&#8217; but, for the consumer, ease of use is going backwards.</p><p><strong>The Challenge</strong></p><p>The challenge is &#8216;what to do next?&#8217;.&nbsp; Shall we grin and bear Identity 2?&nbsp; No, that cannot be countenanced in an age of metaverse and web 3 - we must progress.&nbsp; The challenge, as it is generally understood in the Identity world, is how to get from Identity 2 to Identity 3.&nbsp; My position differs &#8211; Identity 3 cannot be achieved for a decade or two, so Identity 2.5 is the only way forward!&nbsp; I&#8217;ll describe my reasons for such an outlandish statement in my next newsletter.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[8. Identity Paradigms]]></title><description><![CDATA[Generalizing Identity and considering futures.]]></description><link>https://www.newsletters.identity25.com/p/9-identity-in-a-nutshell</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/9-identity-in-a-nutshell</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Tue, 27 Jun 2023 08:49:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2jod!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2jod!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2jod!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 424w, https://substackcdn.com/image/fetch/$s_!2jod!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 848w, https://substackcdn.com/image/fetch/$s_!2jod!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 1272w, https://substackcdn.com/image/fetch/$s_!2jod!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2jod!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png" width="1456" height="1090" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1090,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:462134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2jod!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 424w, https://substackcdn.com/image/fetch/$s_!2jod!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 848w, https://substackcdn.com/image/fetch/$s_!2jod!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 1272w, https://substackcdn.com/image/fetch/$s_!2jod!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfe3ca64-b615-46ce-8a7d-6c4778a6ef8a_2919x2186.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a bit late.  Why - because I rewrote it twice.  It is important so I hope it worked out!</p><p>The title of this newsletter is Identity Paradigms.&nbsp; The aim is to indicate both where we are now and future possibilities.&nbsp; This is not a roadmap, it is a list of paradigms.</p><p>But what is a paradigm?  The word, made famous by Thomas Kuhn in 1962 in <em>The Structure of Scientific Revolutions</em>, depicts a theoretical movement or a way of working with a common basis.  The best example are three paradigms from physics: Newtonian physics, relativity, and quantum mechanics.  In these three paradigms of physics, the underlying theoretical basis changes hugely.</p><p>Identity is more practically focused, so the Identity paradigms are based on the underlying technology-basis.&nbsp; This is the prime driver of Identity and supersedes any ideological or theoretical considerations.</p><p>Please note that:</p><ol><li><p>These are generalized paradigms, not rigorous definitions.  Use them to have efficient discussions.  Do not treat them as defining principles.</p></li><li><p>The horizontal axis generally indicates progress through time, but it is clearly not linear and it varies by sector/industry/country.</p></li><li><p>The vertical axis is more reliable as it reflects how technology develops over time.</p></li><li><p>Each paradigm may include the use of other paradigms.  There is no exclusivity in Identity!  For example, many solutions/sectors currently in Identity 2 utilize components of Identity 0.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K2rI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K2rI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 424w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 848w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 1272w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K2rI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png" width="1456" height="779" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:779,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:84375,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!K2rI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 424w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 848w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 1272w, https://substackcdn.com/image/fetch/$s_!K2rI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e31e1c2-6cff-4f0e-92b0-2f4a787eed00_3201x1712.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Identity 0 &#8211; Knowledge</strong> includes the oldest recorded use of an Identity technique when Odysseus returned from the Trojan War, over 3,000 years ago, and was identified by remembering a secret only he could know.&nbsp; A more generalized knowledge technique is passwords and, as we all know, this age-old technique is alive and well today (well, maybe just alive).</p><p><strong>Identity 1 &#8211; Documentation</strong> is also centuries old and has gone through numerous changes, from the use of seals, to watermarks, and now sophisticated technologies such as holograms. &nbsp;However, with modern counterfeiting becoming more sophisticated and available to all, documents are no longer as secure as they once were.</p><p><strong>Identity 2 &#8211; Technology</strong> is currently where most sectors are.&nbsp; There are many varieties of technologies including hardware devices and software apps, techniques such as biometrics, full blown solutions such as behavioral analytics, and methods such as MFA (multi-factor authentication).&nbsp; This is a lot to bundle into one Identity paradigm, but I do so because all these technologies have a common aim of mitigating Identity risk, especially in the on-line world.&nbsp; Mitigation is the current arms race to keep ahead of the criminals.</p><p>It is worth noting the recent trend of Identity companies evolving to become &#8216;orchestration players&#8217; often through mergers and acquisitions.  These new entities combine multiple techniques, as they find that there is no single solution to the Identity problem (examples are Trulioo, Mitek, and Jumio). </p><p><strong>Identity 2.5 &#8211; Networking</strong> doesn&#8217;t get its own whole number as it is essentially an extension of current Identity capabilities, but uses network effects.&nbsp; The highest profile implementations are National Identity Systems in Scandinavia and Estonia which have one highly secure authentication method which is then networked out to other applications and processes.&nbsp; They leverage high-quality databases, such as banks&#8217; customer data, to raise the veracity of the total system, but a key component is the presence of a national identity number scheme that simplify integration challenges.</p><p><strong>Identity 3 &#8211; Decentralization </strong>is a major technology step-change that would see Identity being based in decentralized assets held in the Internet and which would remove the reliance on centralized assets.&nbsp; Blockchain has been seen as a major contributor to this effort, and there are significant standard associations, such as W3C, leading the decentralized push.&nbsp; Decentralization has a certain ideological tinge to it, as it finds &#8216;big business&#8217; to be as much the problem as the criminals who are trying to break down Identity.&nbsp; While Decentralization promises much, it has yet to deliver any significant solutions.</p><h3>Insights</h3><ul><li><p>In <strong>Identity 2 Technology</strong>, the challenges of Identity are being met by &#8216;adding more&#8217;.&nbsp; This is both by making specific methods more sophisticated and by combining methods.&nbsp; The strategy can be summarized as <strong>&#8216;more complexity = more security&#8217;</strong>,&nbsp; While this may mitigate security risk, it comes at the cost of more complexity for the user, as many of us experience every day. So this can be restated as <strong>&#8216;more complexity = poor customer experience = more security&#8217;</strong>.  Who won out of that?</p></li><li><p><strong>Identity 2.5 Networking</strong> essentially uses current networking capabilities and current assets to achieve a more widespread adoption of some standard approaches to Identity.&nbsp; The major success stories have been in codified law countries where intrenched use of national identifiers makes implementing solutions relatively straight-forward.&nbsp; However, this does not mean that this paradigm cannot be implemented in common law countries.</p></li><li><p><strong>Identity 3 Decentralization</strong> promises to be a totally new beginning and to revolutionize identity.&nbsp; If and when successful, it will be a revolution for not just Identity, but for Information Technology in general.&nbsp; However the question is still &#8216;if&#8217;, and the lack of any identifiable solutions suggests that the promise may be beyond current capabilities.</p></li></ul><p>What does this all mean?&nbsp; Well, technology matters and technology is undecided: the performance of Identity 2 is a problem, the potential of Identity 2.5 is not well understood, and the viability of Identity 3 is uncertain.</p><p>The name of my newsletter, Identity 2.5, gives away which paradigm I think we should be aiming for.&nbsp; In my next newsletter, the last in this initial series, I&#8217;ll elaborate on why Identity 2.5 is the future.</p><h3>A final thought</h3><p>As I reflect on this newsletter, it seems as though this is all somewhat self-evident.  I hope you feel the same way and I have been able to create a simple set of paradigms that are intuitively obvious and that facilitate better conversations.</p><p>All the best</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[7. Current and Developing Identity Technology]]></title><description><![CDATA[At last, technology!]]></description><link>https://www.newsletters.identity25.com/p/8-identity-paradigms</link><guid isPermaLink="false">https://www.newsletters.identity25.com/p/8-identity-paradigms</guid><dc:creator><![CDATA[Dr Alan Mayo]]></dc:creator><pubDate>Thu, 01 Jun 2023 23:37:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iZwX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iZwX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iZwX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 424w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 848w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 1272w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iZwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png" width="1456" height="817" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:817,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1541457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iZwX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 424w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 848w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 1272w, https://substackcdn.com/image/fetch/$s_!iZwX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0a955d-a164-4d52-b834-caf8088d8c2d_1920x1078.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At last, in newsletter 7, we have arrived at technology.  Most commentators start with technology because they hope it will be the answer - I started with defining the question in my early newsletters.  Now, I am looking at the context of identity, which includes this newsletter&#8217;s technology building blocks for Identity.  In the next newsletter I will look at possible futures, that is, at possible answers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QUYf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QUYf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 424w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 848w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 1272w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QUYf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png" width="928" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1133656a-b788-4924-abf1-c9cee517e018_928x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:928,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QUYf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 424w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 848w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 1272w, https://substackcdn.com/image/fetch/$s_!QUYf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1133656a-b788-4924-abf1-c9cee517e018_928x300.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This newsletter&#8217;s title, <strong>Current &amp; Developing Identity Technologies</strong>, states the obvious &#8211; we have both:</p><ol><li><p>current technologies that enable Identity solutions (on the left in the diagram above)</p></li><li><p>developing technologies which promise to be &#8216;the answer&#8217; to Identity (on the right in the diagram above)</p></li></ol><p>In this newsletter I summarise each technology area and what it means for Identity.&nbsp; But to start with, I will discuss the one technology that is fundamental to so much Identity: cryptography.</p><h3>Cryptography</h3><p>Symmetric and asymmetric cryptography (also called private key and public key cryptography) are core to Identity.&nbsp; They are the basis of PINs on cards, secure communications, blockchain, decentralization, and many hardware solutions. Cryptography is how to keep things secret, and it is important, full of jargon, and complex.&nbsp; If you want to develop a deep understand of Identity, you need to understand cryptography!  But beware, it is a deep rabbit hole.</p><h3>Current Technologies</h3><h4>Physical Identity</h4><p>This is where so much identity has started.&nbsp; Documents include passports and birth certificates.&nbsp; Clearly passports have evolved significantly to include a chip.&nbsp; Cards include driver&#8217;s licenses, student identity, club identity, and corporate identity.&nbsp; These all have evolved with different uses of watermarks and tamperproof coatings.</p><h4>Customer Databases</h4><p>CRMs and their predecessors, accounts receivable systems, are a fundamental part of the Identity solution - they are where Personal Identity Information is stored! &nbsp;</p><h4>Hardware Tokens</h4><p>There are a variety of devices such as dongles, challenge-response devices, and code-generating devices that operate in the on-line environment by connecting through a USB port.  They can also generate codes for other environments.&nbsp; They have obvious security benefits but suffer from the need to both distribute and maintain the devices, and from the challenge of interfacing with multiple platforms.</p><h4>SSL</h4><p>SSL, or Secure Sockets Layer, is something we all use on a daily basis.&nbsp; And for good reason &#8211; it is the most important security protocol invented.&nbsp; Based upon asymmetric and symmetric cryptography, it enables secure point to point on-line communications.&nbsp; Without it, on-line Identity, and the internet itself, would be very compromised.</p><h4>Messaging</h4><p>The advent of multi-factor authentication (MFA) requires the customer to have something, often a smartphone.&nbsp; The confirmation that the customer owns the smartphone or device is achieved normally through the entry of a code delivered through some messaging service, such as SMS or email.&nbsp; Messaging is now an established technology used for Identity.</p><h4>Biometrics</h4><p>Biometrics has been with us for decades and is now becoming ubiquitous, due to face imaging and finger print readers on laptops/ PCs and smartphones.&nbsp; It is now hard to imagine a world without biometrics.  But it is far from complete, with developing standards, and threats from such things as AI generated deep-fakes.  This is a technology that will be very important in the future, especially if it can be securely implemented.</p><h3>New Technologies</h3><h4>Behavioural Analytics</h4><p>Behavioral analytics is a development from big data that uses AI like techniques of data analysis.&nbsp; It has utility for general analysis processes such as providing a credit rating for a future borrower, and for predicting if a payment is fraudulent.&nbsp; For Identity, measures of physical behaviour (e.g. the pattern of typing) through to more long-term contextual events can be analysed by behavioural analytics to add an extra dimension to an Identity Authentication process.  The question is: &#8216;is it worth it?&#8217;  Perhaps if we cannot develop good authentication we need such a backup solution, but it seems like a lot of technology to solve a simple problem.  </p><h4>FIDO Passkey</h4><p>FIDO has long been based upon a Hardware Token, but on 5 May 2023 it announced with Microsoft, Google, and Apple an initiative to create a passkey to replace passwords.&nbsp; This is based upon asymmetric cryptography and will potentially eradicate passwords, and thus password stuffing attacks.&nbsp; It may also make customers dependent on a centralized passkey register run by you know who: Microsoft, Google, and Apple.&nbsp; It all feels a bit centralized and big tech to me.&nbsp; This will be the subject of a newsletter quite soon (as will all of these new technologies).</p><h4>Digital Wallets</h4><p>Some pundits think Digital Wallets will answer all our problems.&nbsp; If they are secure, there is much potential to go beyond basic payment wallets such as Apple Pay and Google Pay, to a functional Identity Wallet.&nbsp; The EU&#8217;s approach is to legislate an EU Identity Wallet into existence.  Such an approach is risky, as it does not consider technical feasibility and indeed, one of the initial proposals, now taken down, did recognize the possible need for &#8216;hardware security&#8217;.&nbsp; That little question of security on a consumer digital device is an important one and one that will come often.</p><h4>Blockchain</h4><p>Once the answer to all things digital, Blockchain still is a significant industry and cannot be counted out as at least part of an Identity solution.&nbsp; The biggest challenge is that blockchain is a open, distributed ledger and such an approach is the antithesis of what Identity is trying to do &#8211; keep things private.&nbsp; There are, of course, smart people who can find ways to make blockchain work differently, but why bother?  If blockchain is not designed for privacy, why try to make it support privacy applications?</p><h4>Decentralisation</h4><p>Self-Sovereign Identity (SSI) was all the rage for a few years and the World Wide Web Consortium (W3C) has done a lot of work promoting decentralized standards.&nbsp; The initial push from W3C was to create Decentralized Identifiers (DIDs) and the push is now to utilize Verified Credentials (VCs).&nbsp; DIDs do not appear to have taken off, possibly due to that little problem of security on a consumer digital device.&nbsp; If one was sceptical, one might suggest that the decentralization guys have given up on DIDs, and are now pursing the 2nd prize of VCs.&nbsp; If so, fair enough, but while VCs are a proven technology, the practical use of them may cause more issues than the problems they solve.</p><h3>Insights</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!13gt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!13gt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 424w, https://substackcdn.com/image/fetch/$s_!13gt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 848w, https://substackcdn.com/image/fetch/$s_!13gt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 1272w, https://substackcdn.com/image/fetch/$s_!13gt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!13gt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png" width="928" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:928,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!13gt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 424w, https://substackcdn.com/image/fetch/$s_!13gt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 848w, https://substackcdn.com/image/fetch/$s_!13gt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 1272w, https://substackcdn.com/image/fetch/$s_!13gt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4334b2e-6907-4623-a2f4-4b579f24b4ba_928x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There are multiple insights into technology:</p><ul><li><p><strong>There are many diverse technologies</strong> &#8211; this is not a simple or a consistent field.&nbsp; There are many diverse technologies that support Identity processes.</p></li><li><p><strong>Current technologies are enablers of poorly performing Identity </strong> - current technologies enable current Identity solutions, but as previously discussed in newsletters 4 and 5, current solutions perform poorly.  </p></li><li><p><strong>Biometrics, a current technology, will develop further and will be important</strong> - intrinsically, because of its uniqueness-based authentication power, biometrics is a key part of the future of Identity.</p></li><li><p><strong>Developing technologies are technology driven, not functionality driven </strong>- there is nothing inherently wrong in a new technology approach of seeking new applications for a technology.  But at some point in time, the technology&#8217;s suitability and practicality need to be questioned.  In many of these developing technologies, such questions have not yet been raised.</p></li><li><p><strong>Many developing technologies are unproven </strong>- the inherent insecurity of a customer digital device has yet to be solved in a comprehensive manner.</p></li></ul><p>So, there it is for current and developing technologies.  Lots has happened and lots is happening, and some of it is good, and none of it is comprehensive, and some of it may not work at all.</p><h3>Summary</h3><p>This and the previous newsletter considered the broader context of Identity:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7p1i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7p1i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 424w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 848w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 1272w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7p1i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png" width="942" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5582422-2c8e-4bb7-a87c-484459036023_942x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:942,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169901,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7p1i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 424w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 848w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 1272w, https://substackcdn.com/image/fetch/$s_!7p1i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5582422-2c8e-4bb7-a87c-484459036023_942x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Together, Market Segments and Current &amp; Developing Technologies show:</p><ul><li><p>a muddle of a market and</p></li><li><p>technologies that under perform or are unproven.</p></li></ul><p>I feel that we are in the uncomfortable stage of an evolution, a bit like the lyrics from a Stealers Wheel song: &#8220;Clowns to the left of me, Jokers to the right, here I am stuck in the middle with you&#8221;.</p><p>Regards</p><p>Alan</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.newsletters.identity25.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Identity 2.5! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>