<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Yarmo - identity</title>
    <subtitle>Blog of an Open Source developer</subtitle>
    <link rel="self" type="application/atom+xml" href="https://yarmo.eu/tags/identity/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://yarmo.eu"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2020-07-12T16:23:31+00:00</updated>
    <id>https://yarmo.eu/tags/identity/atom.xml</id>
    <entry xml:lang="en">
        <title>The Future of Online Identity is Decentralized</title>
        <published>2020-07-12T16:23:31+00:00</published>
        <updated>2020-07-12T16:23:31+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/future-online-identity-decentralized/"/>
        <id>https://yarmo.eu/blog/future-online-identity-decentralized/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/future-online-identity-decentralized/">&lt;h2 id=&quot;Online_identity&quot;&gt;Online identity&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Online_identity&quot;&gt;Online identity&lt;&#x2F;a&gt; refers to the concept of &amp;quot;being&amp;quot; in the digital world. As an internet user, you exist. You create accounts on websites. You write on social media and blogs. You post photos. All this online activity has in common that one and the same person performed these actions; it defines your &amp;quot;online identity&amp;quot;.&lt;&#x2F;p&gt;
&lt;p&gt;However, your &amp;quot;online identity&amp;quot; is not &lt;em&gt;per se&lt;&#x2F;em&gt; representative of your &amp;quot;social identity&amp;quot; in the physical world.&lt;&#x2F;p&gt;
&lt;p&gt;You may choose to use your own name or a pseudonym. You may choose to publish personally identifiable information or not. You may choose to remain truthful to your social identity or deceive. In short, you may choose for authenticity or for anonymity.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Authenticity_versus_anonymity&quot;&gt;Authenticity versus anonymity&lt;&#x2F;h2&gt;
&lt;p&gt;Authenticity and anonymity aren&#x27;t mutually exclusive and that is the beauty of the internet. In the physical realm, you are (mostly) limited to a single social identity. In the digital space, there are no such restrictions. While you can&#x27;t embody multiple persons in the offline world, you can have several identities online. In fact, you can even have multiple accounts on the same platform, opting for a different balance between authenticity and anonymity for each one of them.&lt;&#x2F;p&gt;
&lt;p&gt;The anonymity has its downsides, creating psychological artifacts like &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Online_disinhibition_effect&quot;&gt;online disinhibition&lt;&#x2F;a&gt; and facilitating &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cyberbullying&quot;&gt;cyberharassment&lt;&#x2F;a&gt;. However, even though we are far from completely overcoming these challenges, the internet that allows us to remain anonymous is still the one we should want and fight for.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Consolidation_of_identity_and_internet_corporations&quot;&gt;Consolidation of identity and internet corporations&lt;&#x2F;h2&gt;
&lt;p&gt;Removing the possibility for anonymity could solve the problem of online toxicity. Large internet corporations like Google and Facebook allow all to create an account on condition that some personally identifiable information is revealed, usually a phone number.&lt;&#x2F;p&gt;
&lt;p&gt;The benefit is that it deters most from repeatably creating new accounts when older accounts have been flagged or banned due to improper behavior. These companies gain the function of &amp;quot;identity provider&amp;quot;: they manage your online identity that can be used to login in different locations of the internet. We all know many websites that offer a &amp;quot;Google login&amp;quot; or &amp;quot;Facebook login&amp;quot;.&lt;&#x2F;p&gt;
&lt;p&gt;But there is a problem: handling the entire online identity of a single person is too much responsibility for any corporation or organization, especially if it is in their interest to gain intimate individual knowledge and sell it (Google) or use it to manipulate moods and influence decision making (Facebook).&lt;&#x2F;p&gt;
&lt;p&gt;That phone number that was once used to prevent online toxicity is now the first of many pieces of personally identifiable information that these corporations will seek and use to figure out who you are.&lt;&#x2F;p&gt;
&lt;p&gt;&amp;quot;You have nothing to hide&amp;quot;? Great. The internet corporations will still make money hand over fist by selling your personality, your preferences, your buying patterns and your vote. And not just yours. That of entire populations.&lt;&#x2F;p&gt;
&lt;p&gt;Know that profits are just the tip of the iceberg. Governments all around the world are also interested in knowing what their citizens think, say and do for very different motives.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Going_decentralized&quot;&gt;Going decentralized&lt;&#x2F;h2&gt;
&lt;p&gt;The solution is relatively simple. When you create a new account and get to choose between &amp;quot;Google login&amp;quot;, &amp;quot;Facebook login&amp;quot; and &amp;quot;Email login&amp;quot;, pick &amp;quot;Email login&amp;quot;.&lt;&#x2F;p&gt;
&lt;p&gt;The benefit of not giving away any more personal data and tracking possibilities outweigh the inconvenience of having to fill in your email address and a password, especially when using a password manager. As tempting as the alternative is, making these changes will improve your life and ultimately, when enough people join these efforts, that of the world population.&lt;&#x2F;p&gt;
&lt;p&gt;A different problem arises: how to prove online identity when decentralized?&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Decentralized_online_identity&quot;&gt;Decentralized online identity&lt;&#x2F;h2&gt;
&lt;p&gt;When you are no longer relying on an identity provider to manage your entire online identity, you lose the one common thing all your accounts on different platforms had: if two accounts on different online platforms are created by the same Google or Facebook account, we can safely assume they belong to the same person.&lt;&#x2F;p&gt;
&lt;p&gt;But this &amp;quot;trust by proxy&amp;quot; is lost when the accounts on those platforms were created without identity provider. And whether authentic or anonymous, it can sometimes be extremely useful to know and trust that separate accounts on the internet belong to the same person, even when not knowing who this person is.&lt;&#x2F;p&gt;
&lt;p&gt;The username is not sufficient to identify accounts across platforms. If you are &amp;quot;Alice&amp;quot; on one website, chances are you might need to be &amp;quot;Alice123&amp;quot; on the next one. And what if someone close to you is contacted by an &amp;quot;Aliss&amp;quot; requesting an amount of money to be transferred because they believe you to be in some sort of trouble? A poor attempt at impersonation, I know… Don&#x27;t worry, a real bad actor will put in more effort and make a much more convincing act.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Proving_decentralized_online_identity&quot;&gt;Proving decentralized online identity&lt;&#x2F;h2&gt;
&lt;p&gt;What if not only your online identity is decentralized, but also the tool to prove said online identity? This would mean that you wouldn&#x27;t need to depend on a single company or entity to prove your identity across platforms. Decentralized identity, decentralized proofs!&lt;&#x2F;p&gt;
&lt;p&gt;Such solutions are already being deployed in industry, for example by firms like &lt;a href=&quot;https:&#x2F;&#x2F;indicio.tech&#x2F;&quot;&gt;Indicio.tech&lt;&#x2F;a&gt; which focus on blockchain technology.&lt;&#x2F;p&gt;
&lt;p&gt;Built for individuals, I recently launched &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide&lt;&#x2F;a&gt; which uses cryptographic keypairs to accomplish decentralized identity verification. While it doesn&#x27;t (and shouldn&#x27;t!) link an account to a person in the physical realm, it links accounts across platforms.&lt;&#x2F;p&gt;
&lt;p&gt;If you trust an account on one platform, you can trust any other account on any other platform as long as they are both verified by &amp;quot;identity proofs&amp;quot; stored in the same keypair. Whether you choose authenticity or anonymity, decentralized identity proofs allow you to build a cross-platform online identity.&lt;&#x2F;p&gt;
&lt;p&gt;Here&#x27;s my &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&quot;&gt;Keyoxide profile&lt;&#x2F;a&gt;. In this case, I link to several &amp;quot;authentic&amp;quot; accounts but I could easily generate a new keypair void of personal data that links to several anonymous accounts. The accounts don&#x27;t need to be authentic to create an online persona.&lt;&#x2F;p&gt;
&lt;p&gt;All the accounts listed in the link above belong to me. No one else could claim these accounts. Here&#x27;s how.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Identity_proofs&quot;&gt;Identity proofs&lt;&#x2F;h2&gt;
&lt;p&gt;An &amp;quot;identity proof&amp;quot; is nothing more than a link to an account A on some platform P stored inside your keypair K. If a &amp;quot;proof verification tool&amp;quot; such as Keyoxide follows this link and discovers some piece of data linking back to keypair K (which is only possible if keypair K and account A on platform P belong to the same person), the account is verified. If this proof verification is done for several accounts on different platforms, it is beyond reasonable doubt that the same person owns said accounts.&lt;&#x2F;p&gt;
&lt;p&gt;No bad actor could claim one of your accounts: the piece of data that links back is specific to your keypair, not the bad actor&#x27;s keypair. And the bad actor also couldn&#x27;t insert a proof inside your keypair as long as your keypair isn&#x27;t compromised. Only you, the owner of the keypair, can add new proofs. But the entire world can read and verify them.&lt;&#x2F;p&gt;
&lt;p&gt;These identity proofs are decentralized because Keyoxide doesn&#x27;t store them, your cryptographic keypair does. Keyoxide simply reads the keys and verifies the proofs. When you remove a proof from your keypair, Keyoxide will no longer have access to it. You own your proofs and your online identity.&lt;&#x2F;p&gt;
&lt;p&gt;In fact, the proofs are readable by everyone and are not specifically designed for Keyoxide. Anyone can use any tool or create new ones to verify these proofs and developers are encouraged to enrich this field with additional tools and services. Let&#x27;s build a decentralized identity ecosystem we can all trust.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Online_identity_beyond_today&#x27;s_internet&quot;&gt;Online identity beyond today&#x27;s internet&lt;&#x2F;h2&gt;
&lt;p&gt;Initiatives like &lt;a href=&quot;https:&#x2F;&#x2F;inrupt.com&#x2F;solid&quot;&gt;Solid&lt;&#x2F;a&gt; by &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Tim_Berners-Lee&quot;&gt;Sir Tim Berners-Lee&lt;&#x2F;a&gt; are paving the way for a new internet where all data is owned by the user and shared with platforms with consent and restrictions. This would solve the online identity problem: you get the benefits of a &amp;quot;pseudo centralized&amp;quot; account while maintaining full ownership over all account-related data stored on a decentralized platform. Social media would be allowed to see some data, messaging platforms some other data. But there would still be one single account to rule all the platforms.&lt;&#x2F;p&gt;
&lt;p&gt;On today&#x27;s internet, the best we can do is make fully separated accounts, link them using technologies like decentralized online identity proofs and create our own online personas, with our own open tools that ensure we maintain ownership over them.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Launching Keyoxide.org</title>
        <published>2020-07-01T12:00:00+00:00</published>
        <updated>2020-07-01T12:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keyoxide/"/>
        <id>https://yarmo.eu/blog/keyoxide/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keyoxide/">&lt;p&gt;Today, I&#x27;m excited to launch &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt;, the lightweight and FOSS solution to make basic cryptography operations accessible to regular humans.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_is_Keyoxide.org?&quot;&gt;What is Keyoxide.org?&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; offers easy encryption, signature verification and decentralized identity proof verification based on PGP keys while demanding little in-depth knowledge about the underlying encryption program from its users.&lt;&#x2F;p&gt;
&lt;p&gt;This project aims to offer comparable functionality as services like &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&quot;&gt;Keybase&lt;&#x2F;a&gt; while reducing friction and being more open.&lt;&#x2F;p&gt;
&lt;p&gt;The project is MIT licensed, uses &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;openpgpjs&#x2F;openpgpjs&quot;&gt;openpgpjs&lt;&#x2F;a&gt; and is hosted on &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Codeberg&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Why_only_encryption_and_signature_verification?&quot;&gt;Why only encryption and signature verification?&lt;&#x2F;h2&gt;
&lt;p&gt;These are the operations that are available when only having access to public keys instead of private keys. If you wish to decrypt messages and sign them, you need a keypair. If you have a keypair, you probably have the knowledge to use dedicated tools like the CLI or Kleopatra. And if you do, you probably won&#x27;t be using &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; directly yourself.&lt;&#x2F;p&gt;
&lt;p&gt;Indeed, if you possess a PGP keypair, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; is the tool you send to others to interact with your public key more easily. Allow them to encrypt a message for you, to verify one of your signatures, to verify your online identities using decentralized proofs.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_are_those_decentralized_identity_proofs_you_keep_mentioning?&quot;&gt;What are those decentralized identity proofs you keep mentioning?&lt;&#x2F;h2&gt;
&lt;p&gt;You know how Keybase allows you to prove you have control over accounts on certain websites and services? A great function! Fortunately for you, this function can be even better and more secure by using &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;openpgp-proofs&quot;&gt;decentralized OpenPGP identity proofs&lt;&#x2F;a&gt;. &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; will prove your identity on multiple platforms at the same time and yet, you are not required to make an account to use this function. How is that possible?&lt;&#x2F;p&gt;
&lt;p&gt;Well, it&#x27;s called &lt;em&gt;decentralized&lt;&#x2F;em&gt; for a reason: &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; doesn&#x27;t hold your proofs, your key does! Any software that can access your public key can verify these proofs for anyone. When better tooling comes around, you could verify those proofs using a mobile app, using a command-line utility, you name it. No single service holds your proof, only you do, stored inside your keypair.&lt;&#x2F;p&gt;
&lt;p&gt;I have written a &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&quot;&gt;guide&lt;&#x2F;a&gt; on how to add a proof for every platform currently supported by this website: &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;dns&quot;&gt;domains&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;lobsters&quot;&gt;Lobste.rs&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;twitter&quot;&gt;Twitter&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;github&quot;&gt;Github&lt;&#x2F;a&gt;, a &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&quot;&gt;bunch more&lt;&#x2F;a&gt; and work is in progress to support even more still. Is your beloved service not in the list? &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Open an issue or make a PR&lt;&#x2F;a&gt;! Free open-source software FTW!&lt;&#x2F;p&gt;
&lt;p&gt;Oh, that reminds me, any &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;mastodon&quot;&gt;Mastodon&lt;&#x2F;a&gt; instance can be used to prove your identity. Yes, &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;keybase-issues&#x2F;issues&#x2F;3385&quot;&gt;any&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;So_how_does_it_compare_to_Keybase?&quot;&gt;So how does it compare to Keybase?&lt;&#x2F;h2&gt;
&lt;p&gt;There&#x27;s a more complete &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;feature-comparison-keybase&quot;&gt;guide on the Keyoxide website&lt;&#x2F;a&gt;, but in a nutshell:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;more privacy-friendly by not forcing you to create an account and handing over data&lt;&#x2F;li&gt;
&lt;li&gt;more secure by not asking you to trust the service with your private keys&lt;&#x2F;li&gt;
&lt;li&gt;open-source servers (&lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;client&#x2F;issues&#x2F;24105&quot;&gt;a must&lt;&#x2F;a&gt;)&lt;&#x2F;li&gt;
&lt;li&gt;encrypt&#x2F;verify with every public key accessible on the internet, not just those that have been uploaded to a proprietary server&lt;&#x2F;li&gt;
&lt;li&gt;almost all processing is done in the browser, no data is sent to servers*&lt;&#x2F;li&gt;
&lt;li&gt;no vendor lock-in&lt;&#x2F;li&gt;
&lt;li&gt;selfhostable&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;* Only exception is decentralized identity proof verification: some service providers do not have the correct CORS headers (like Reddit) or require APIs (like Twitter). In these rare cases, simple PHP scripts (also open-source) run the proof verification instead.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Can_I_get_an_account?&quot;&gt;Can I get an account?&lt;&#x2F;h2&gt;
&lt;p&gt;No. &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; doesn&#x27;t need your data on its servers. There are already several ways of exposing public keys on the internet, including &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;guides&#x2F;web-key-directory&quot;&gt;web key directory&lt;&#x2F;a&gt; (WKD) and dedicated servers like &lt;a href=&quot;https:&#x2F;&#x2F;keys.openpgp.org&quot;&gt;keys.openpgp.org&lt;&#x2F;a&gt;. Let&#x27;s use those instead of making yet another service where you need to upload your keys to.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Can_I_get_a_profile_page_then?&quot;&gt;Can I get a profile page then?&lt;&#x2F;h2&gt;
&lt;p&gt;Yes! Append your PGP fingerprint or WKD id to the URL and there it is!&lt;&#x2F;p&gt;
&lt;p&gt;Want an example? Here&#x27;s  my profile at&lt;br &#x2F;&gt;
&lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&quot;&gt;https:&#x2F;&#x2F;keyoxide.org&#x2F;9f0048ac0b23301e1f77e994909f6bd6f80f485d&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;Now you know what accounts on various services are mine, where to follow me if you wish to get updates on the project and if you wish to send me an encrypted message, that&#x27;s also just two clicks away.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_about_my_private_keys?&quot;&gt;What about my private keys?&lt;&#x2F;h2&gt;
&lt;p&gt;Don&#x27;t upload your private keys to the internet, period. If a service wants your private keys on their (proprietary) servers, say no.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;You_said_selfhostable?&quot;&gt;You said selfhostable?&lt;&#x2F;h2&gt;
&lt;p&gt;Well, yes! It&#x27;s not a fully supported use case just yet, but the browser does all the processing, the server is mostly just there to deliver the files to the user to perform the operations. &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&quot;&gt;Grab the code&lt;&#x2F;a&gt; and put it on your own PHP server!&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Any_closing_words?&quot;&gt;Any closing words?&lt;&#x2F;h2&gt;
&lt;p&gt;I built this to provide better tooling around modern-day encryption programs and reduce the friction for less tech-savvy people when interacting with public keys.&lt;&#x2F;p&gt;
&lt;p&gt;For those who wish to use encryption programs beyond OpenPGP, &lt;a href=&quot;https:&#x2F;&#x2F;codeberg.org&#x2F;yarmo&#x2F;keyoxide&#x2F;issues&quot;&gt;let&#x27;s talk about this&lt;&#x2F;a&gt;. Keyoxide doesn&#x27;t have any reference to PGP in its name for a reason: it could serve as a platform for easy interaction with any public key, no matter the underlying encryption program.&lt;&#x2F;p&gt;
&lt;p&gt;And above all, I hope you see the same benefit and potential in &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; as I do and would like to see it grow as an open and accessible platform to push forward the democratization of online privacy and security.&lt;&#x2F;p&gt;
&lt;p&gt;Privacy is not a luxury.&lt;&#x2F;p&gt;
&lt;p&gt;Many thanks to &lt;a href=&quot;https:&#x2F;&#x2F;metacode.biz&#x2F;@wiktor&quot;&gt;Wiktor&lt;&#x2F;a&gt; for helping with the decentralized identity proofs.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
