🤔“If we invest too much in AI and too little in developing the human mind, the very sophisticated artificial intelligence of computers might serve only to empower the natural stupidity of humans, and to nurture our worst…impulses” https://www.theatlantic.com/magazine/archive/2018/10/yuval-noah-harari-technology-tyranny/568330/

👍👏“If you dislike the idea of living in a digital dictatorship or some similarly degraded form of society—then the most important contribution you can make is to find ways to prevent too much data from being concentrated in too few hands.”—@harari_yuval https://www.theatlantic.com/magazine/archive/2018/10/yuval-noah-harari-technology-tyranny/568330/

If you wish to support building self-sovereign identity, join us or sponsor our 7th #RebootingWebOfTrust in Toronto on Sept 26th -28: https://rwot7.eventbrite.com A substantial discount available if you submit topic paper in advance.

I love this real world use case. In the same way that we’ve begun to democratize payments, how can we bring the 5-7 most common finance contracts to the P2P level in places like Kenya & Bangladesh? https://twitter.com/pesa_africa/status/1035852520256692225

T.H.I.N.K. (True, Helpful, Inspiring, Necessary, Kind) Close to my own criteria, though in my own algorithm for Helpful if I’m sharing something from someone else I like to either add some new substance, context or connection to another idea. Always grow the intellectual commons! https://twitter.com/bechillcomedian/status/1034776443446849536

The challenge with many of these approaches is they are incredibly inefficient. At Blockchain Commons we are working on zkp Bulletproofs SecP & mirror SecQ that allow for some opportunities for zero-knowledge proofs that are quite efficient. https://github.com/BlockchainCommons/secp256k1/issues/1#issuecomment-410482607

Also remember that an operational privacy contract between two parties can be quite computationally inefficient (given its value to those two parties) if verifing the contract by others is easier.

Funny but unfortunately too true video about new anti-privacy backdoor mandate law being proposed in Australia. https://youtu.be/eW-OMR-iWOE

Excellent infographic on why the confidentiality promised by Bitcoin is important for not only for personal privacy but also important for business. We are not quite all the way there yet, but progress! https://twitter.com/patestevao/status/1036719305818296321

It is great to hear that Holland is doing a self-sovereign identity system! https://arxiv.org/pdf/1806.01926.pdf I’m in talks with a couple of other governments also considering this — anyone have some good contacts there? https://twitter.com/trbouma/status/1036352040384036865

I have a book @MeeplesTogether on the design of cooperative board games (in collaboration with @Appelcline) coming out this year, with among other things covers the modern history of these game designs. But nothing on this. Any references?

Back in the MUD/MUSH days this was known as an emote. It also became abused as there was no consent. In a series of games at #Skotos in early 00’s I designed something called the Consent System to try to address this problem in text games http://www.skotos.net/articles/chezskoot.html /ht @TaylorLorenz https://twitter.com/TaylorLorenz/status/1037040718492192768

It worked quite well and is still in use in text dominant game Castle Marrach. More details on what we actually implemented at https://github.com/skotostech/SkotOS/blob/master/docs/Story_Builder/ConsentSystem.md

The full technical details of the Skotos ConsentSystem are at https://github.com/skotostech/SkotOS/blob/master/docs/Story_Builder/ConsentSystem.md — I’ve slowly been trying to convert all of our text game libraries & docs to open source.

👉@kimdhamilton @drummondreed

This looks interesting. I was not aware of event.

Sounds like a good time for a self-sovereign identity breakfast!

Transcript at http://transcripts.cnn.com/TRANSCRIPTS/1809/02/fzgps.01.html

My concern is that later he commends #Aadhaar.

True 👍 I feel like we are in the WAIS/Gopher era of blockchain evolution. The basics are in place (TCP/IP) and some protocols will survive but will need to be transformed (telnet/ftp), but we have no http much less a Netscape implementation to dominate it, to then be superseded. https://twitter.com/nlw/status/1036779014130741249

I will be in Lyon at end of October — looking for some patronage to extend stay in EU.

One of the best articles on why privacy tech important to business is from the US St.Louis Fed “Privacy in payments is desired…for protection from malfeasance or negligence by counterparties or by the payments system provider itself.” https://research.stlouisfed.org/publications/review/2018/07/16/payment-systems-and-privacy

Thu Sep 06 17:59:12 +0000 2018

It’s not clear to me that $0.02 is the true price of a SWIFT transaction, given the amount charged to customers of banks to transfer funds. Beyond those costs there are many intangible costs: regulatory, latency/delay, compliance, conformance to local laws & US requirements.

I can’t help but think of the F2F gaming & LARPing possibilities of AR cut & paste. My thoughts are full of ideas like magical amulets & thoughts of “Mirror, mirror on the wall…” https://twitter.com/laanlabs/status/1037739442650243072

I’m not sure. There is an argument that the true cost of a bitcoin transaction should include the block award. Which at least is fairly easy to measure and transparent, whereas SWIFTs true costs are very opaque, which allows middlemen to take undue advantage.

Ultimately the problem with URLs is they did not evolve into persistent URNs like they were supposed to. What is interesting about DIDs (decentralized identifiers) & content addressable hashes (like IPFS) is that they could also be used to serve as a basis for uncensorable URNs. https://twitter.com/judell/status/1037537440263618560

Good overview of Token-Curated Registry pros & cons. I’ve been intrigued by TCRs for some time, but have been puzzled on how to implement using Bitcoin & LN. Have some ideas on how to do it with #SmartSignatures & Cryptographic Object Capabilities but we need Schnorr in Bitcoin. https://twitter.com/KyleSamani/status/1037728136035741696

Agreed. But they are a better underlying layer than URLs were to URNs.

A number of interesting new advance reading topic papers posted for upcoming #rwot7 including two on local/pet names, several on discovery & integrity of content, some thoughts on decentralized error reporting, zk for DIDs & DAD and much more! https://github.com/WebOfTrustInfo/rwot7/blob/master/README.md

Come join us and shape the leading edge of decentralized self-sovereign identity! Large discount through 9/23 if you too submit an advance reading topic for the community to consider. Design Workshop is September 26-28 in Toronto. https://rwot7.eventbrite.com

I’m in Taiwan today. With my work on human rights identity I’m feeling very sympathetic to the 23.5 million people here that have only 17 nation state allies left in the world due to economic & political pressures applied by China. https://twitter.com/wxw_tw/status/1039371485121404928

I think in the future historians will consider this decade to be fundamentally about changes to the nature of sovereignty. #Taiwan, #SpratleyIslands, #Estonia, #Crimea, #Brexit, #Kurdistan, #Catalonia, #Cal4, etc. I want people to have voice & protection #SelfSovereignIdentity

I ran out of room. So many different levels of sovereignty—#Quebec, #Rohungya, cities so big they should split up, adjoining towns growing so fast they should merge, companies so dominant they should be split up. etc. Individuals should not be supplicants in these decisions.

Introduced by @philchen913 of @htcexodus, we met with Jason Hsu @augama Taiwanese at-large legislator, or as his biz card offers “a.k.a Crypto Congressman”. We had some great discussion on self-sovereign identity and possibilities offered by Taiwan’s unique position in the world.

Wed Sep 12 23:43:59 +0000 2018

I’m seeking an international legal scholar to write up a CC-BY short piece educating us on history & law principles behind “freedom of association” and application of it to digital communication, privacy & censorship resistance. #RebootingWebOfTrust https://en.m.wikipedia.org/wiki/Freedom_of_association

These kind of language subtleties fascinate me. I do believe that they can lead to unconscious differences in ways we behave & believe. https://t.co/c1RaDSzOyV

“The Court found that the UK’s mass surveillance programmes, revealed by NSA whistleblower Edward Snowden, did ‘not meet the “quality of law” requirement’ and were ‘incapable of keeping the “interference” to what is “necessary in a democratic society”’” https://twitter.com/BigBrotherWatch/status/1040175651326767105

I wonder where money comes from in Italian & Greek?

Excellent use of AR in news. https://twitter.com/dorseyshaw/status/1040337184581214209

Even more advance reading topic papers on the future decentralized identity are now available at https://github.com/WebOfTrustInfo/rwot7 We ask attendees to read these before the event to help inform our collaborations during the Design Workshop itself.

Also a useful link is this explanation of the origin of secp256k1’s construction from then IETF SECG Chair Dan Brown: https://bitcointalk.org/index.php?topic=289795.msg3183975#msg3183975

It turns out this construction is quite interesting as it supports a “mirror” curve (which we call “SecQ”) that in turn is a mirror of SecP, potentially offering some recursive Bulletproofs not easily possible with other curves: https://github.com/BlockchainCommons/secp256k1/issues/1#issuecomment-410482607

I was not CTO of Certicom yet when the secp256k1 parameters were selected. I’ll ask Paul Lambert who I think was at Certicom at the time if he knows.

Have you heard yet about @ixoworld lead by @_shaunconway? I’m busy next for couple of weeks due to upcoming https://rwot7.eventbrite.com

I definitely agree trust is non-binary, though my model that I call “progressive trust” it a bit different than your divisions. I tend to map it more around the exchange of signals about risk between the parties: http://www.lifewithalacrity.com/2004/08/progressive_tru.html

None of the various DID methods proposed in the W3C CCG suggest a global unique identity. Instead, they all support making it easier to keep your multiple identities separate and uncorrelatable.

“We need to insert a framework of intentionality into that process so that at the end of our experiments, we have a perspective on how this technology extends our species. What is the purpose of this technology? Can this be a bicycle for the mind or not?” https://render.betaworks.com/building-bicycles-for-our-minds-c79a2dd0b958

Jekyll on GitHub

For discount codes & scholarship requests send to rwot-leadership@googlegroups.com

You might also want to reach out to @agropper of http://hieofone.org

I’d love to get a good translation of this to be able to talk about the scope & scale of the pilots more accurately at next week’s https://rwot7.eventbrite.com

So who was right?

I would like to see more transparency about custody: “Generally accepted methods for auditing virtual assets do not exist, and trading platforms lack a consistent and transparent approach to independently auditing the virtual currency that is purportedly in their possession.” https://twitter.com/NewYorkStateAG/status/1042098555849265152

This is a good start to questions to anyone that has custody of your digital assets, whether an exchange, broker, or your niece who holds your bitcoin for you. https://twitter.com/NewYorkStateAG/status/1042148442871607296

Other questions I would ask: * Has the custodian had independent assessments of digital asset custody procedures? * What risk modeling has the custodian performed and documented? * Who is auditing the digital assets of the organization maintaining custody, audit frequency?

…How are separation of duties applied to your digital asset processes? Does such separation of duties use other firms? Are the digital assets commingled? Are they being rehypotheticated or otherwise leveraged? How benefits from such leveraging, forks, and coin drops?

…I as a more sophisticated investor would probably also ask for more details about their cryptographic practices, such as configuration of cryptographic hardware, security reviews of the hardware and processes, key rotation strategies, etc.

What other questions should you expect good answers from someone who is holding your digital assets on your behalf?

@sphcow any chance you can make it to https://rwot7.eventbrite.com in Toronto next week?

We (@kanzure @CaitlinLong_ @anguschampion @ckayakr) responded to the SEC Letter “Engaging on Fund Innovation and Cryptocurrency-Related Holdings”. Our intent is disclose what we feel are critical considerations for regs on handling cryptocurrencies: https://www.sec.gov/investment/fund-innovation-cryptocurrency-related-holdings

See also our letter to SEC https://twitter.com/christophera/status/1043078344076455936?s=21

Our advice is for SEC to leverage the capability for digital assets to regulate themselves before creating regulations that might undermine that capability. Right now unlimited commingling allows off-chain non-transparent rehypothecation.

I am also working on the issues of custody at exchanges, including improving best practices and educating their customers to demand more transparency about security practices.

Exactly. Also there are ways we can address regulatory needs & preserve confidentiality using tech rather than regulatory mandates—sophisticated multi-sig smart contract scripts, Proof of Reserve/Solvency, Auditable Confidential Transactions, etc. SEC should not block those.

DM for scholarship code.

I particularly don’t want an EFT calling itself a Bitcoin EFT unless it truly represents the qualities of that asset. To leverage & rehypothocate it non-transparently means that you are not benefiting from uniqueness of that underlying asset. Call it something else.

Being in denial that they are already stepping in is part of the problem. If you hold more than $150M of others money the current regs require you to use a qualified custodian, which can in many cases make the digital assets less secure as there are no established best practices.

I suspect the SEC would prefer to see some type of SRO (self-regulatory organization) emerge to codify best practices, but it hasn’t happened yet. Without that they might just regulate it themselves. I am preparing a start for some shared best practices, but we have a ways to go.

I’m actually ok with leveraging if it is transparent to both regulators and investors — cryptographic approaches like proof of reserve/solvency can do this. But bringing 2008 leveraging to Bitcoin is risking what Bitcoin was created for in first place.

See thread https://twitter.com/christophera/status/1042878941680156673?s=21

We are :-) Some workshop content & docs on #SmartCustody in progress. You can subscribe to announcements at https://tinyletter.com/SmartCustody

We are working towards some seminars and documents on best practices for #SmartCustody — if you’d like to get on Announcements List you can subscribe at https://tinyletter.com/SmartCustody

I have been developing some content on best practices for both personal (high net worth) & small advisor (<$150M) management of digital assets, which I started when in was at Blockstream. @kanzure recently architected and deployed an institutional custody system for LedgerX.

I have been saying this for some time, as well as that US$ is used far more for criminal activities. This article is better source than the one I previously RTed, with a link to original Europol PDF. https://twitter.com/CCNDotComNews/status/1042421708702064640

🤔 Thread 👇 https://twitter.com/thedeadauthor/status/1042832087793975297

TMA - too many acronyms. ETF not EFT.

Replying to @HPEC_DAO, @ID2020 and @LeahHoustonMD

I’d be glad to chat further, but the best way to connect is for you to get involved in the #RebootingWebOfTrust community. Our next collaborative event is next week in Toronto https://rwot7.eventbrite.com

I’m seeking from cryptographers & security reviewers common implementation problems & attacks with Shamir Secret Sharing. @satoshilabs is proposing a SSS standard for BIP-32 master keys & I’d like to capture a good issues list. See https://github.com/satoshilabs/slips/blob/master/slip-0039.md https://github.com/satoshilabs/slips/issues/378

Closest I have for BIP-32 what I call “Poor Man’s 2 of 3 Secret Sharing”. 24 word BIP-39 mnemonics, uses words 1-16 on titanium tile, words 1-8 & 17-24 on another, words 9-24 on last. Less theoretical security than SSS but theft of one tile is still impractical to brute force.

Everytime I see a Lightning Node hex address for a LN service, I wish it was a shorter bech32 identifier. TXREF-like but adds output index? @alexbosworth @rusty_twit @roasbeef (See also : https://github.com/bitcoin/bips/pull/555#issuecomment-423766163))

The problem isn’t just licenses to code. Companies often don’t allow employees to own their own code, and there are other forms of fear that are coercive to code expression. Thus the Amira User Story: https://github.com/WebOfTrustInfo/rebooting-the-web-of-trust-fall2017/blob/master/final-documents/amira.md

Focus on invoices is important, but node addresses are important for TOFU (trust on first use) security. You want to know when you successfully use a node’s services that the node can deliver additional services.

I agree that in many cases some kind of multisig on a UTXO is a better form of resilience, but there continue to be cases where the entire master key needs to be recovered. But Shamir is error prone—see thread 👇 https://twitter.com/christophera/status/912776531264512000?s=21

I think it is these kind of practices that will ultimately be €B+ fines against Google in the EU, but possibly only after there is usage of pan-EU eBook sellers mandated by the EU as well. The fines probably would have happened in last round of anti-trust if not Amazon monopoly.

To keep my mind sharp outside my industry I design games (board, card, rpg, social, play-by-email, computer, mobile, online) and play handpan.

Interesting thread with resonance to a broad number of topics, ranging from keeping mind sharp, safe spaces, opsec, and more. 👇 https://twitter.com/tarah/status/1043582965874221056

👎🤬“make linking of Aadhaar or any one of the government-authorized identity proof mandatory for authentication while creating e-mail and other social media accounts” #aadhaar #india #identity https://twitter.com/no2uid/status/1043365440658001920

But I want a Technical Igor!

Actually, Sovrin does not use Hyperledger Fabric — it is its own blockchain approach. This is a common misperception that Hyperledger = Fabric, for instance Sawtooth Lake is yet another alternate Hyperledger blockchain project. There are several more.

There are a number of different projects supporting self-sovereign identity, using different blockchains. Of them, @SovrinID & @VeresOneID have both elected to go with permissioned public architectures. Both are taking the approach of placing nodes under different jurisdictions.

There are multiple implementations of DIDs (decentralized identifiers) on blockchains, only a few chose permissioned blockchains. My job as a leader in this community is to support as much innovation as we can & yet still find ways to work together. The marketplace will decide.

“The real apprehension is that data available can be used to influence election outcome. Will democracy survive if data is used to influence the electoral outcome? We have seen it”—Justice Chandrachud, India Supreme Court https://www.hindustantimes.com/india-news/aadhaar-data-leak-can-influence-election-outcome-says-supreme-court/story-vRRanM53Tx3XuBxsEnN6kL.html

There is an argument (which I don’t necessarily buy, but is interesting) that some permissioned chains have more decentralized than public chain due to of mining pools. If a public chain is dominanted by a few pools, they say a permissioned around world may be more decentralized.

👍“While ownership implies a property law model of our data, we argue that the legal framework for our identity-related data must also consider constitutional or human rights laws rather than mere property law rules.” https://medium.com/@hackylawyER/do-we-really-want-to-sell-ourselves-the-risks-of-a-property-law-paradigm-for-data-ownership-b217e42edffa

These two models (Identity as Property Law vs Identity as Human Right) have clashed in a recent discussion to try to revise the 1st Principal of Self-Sovereign Identity “Existence”. I’d love your advice https://github.com/WebOfTrustInfo/self-sovereign-identity/issues/6

Self-Sovereignt Identity Principal 1: “Existence. Users must have an independent existence. Any self-sovereign identity is ultimately based on the ineffable “I” that’s at the heart of identity. It can never exist wholly in digital form.…”

“…This must be the kernel of self that is upheld and supported. A self-sovereign identity simply makes public and accessible some limited aspects of the “I” that already exists.” http://www.lifewithalacrity.com/2016/04/the-path-to-self-soverereign-identity.html

I’ve always found @OXO products among my favorites kitchen tools due to their effective design, so I enjoyed this story of some of the history of that design: https://www.fastcompany.com/90239156/the-untold-story-of-the-vegetable-peeler-that-changed-the-world

Point them to our joint letter to the SEC: https://twitter.com/christophera/status/1043078344076455936?s=21

“We believe that digital assets are a unique asset class with unique strengths and abilities…We caution against applying rules to digital assets in ways which do not reflect their strengths…”

“…We should leverage the technology of this asset class to protect investors in ways not previously possible… Solutions in this space might be dependent on technology, not policy.”

In Wyoming, there is a new law AB101 that a stockholder can be represented by a network address & key. I’ve been talking with some folk there about using that to enable some corporate governance. cc @CaitlinLong_

DIDs are Network Addresses with Signatures. W3C Credentials CG https://github.com/w3c-ccg/community/blob/master/work_items.md shows a number of work items in progress. I plan to build a corporate shareholder governance wallet for Wyoming LLCs.

Collaborations emerging at our 7th #RebootingWebOfTrust!

Decentralized digital identity topics to be collaborated on have been selected by the #RebootingWebOfTrust 7 participants: 11 abstracts to be finished to first draft quality by Friday! https://github.com/WebOfTrustInfo/rwot7/tree/master/draft-documents

#RebootingWebOfTrust is more of a “do” than a “talk” event, but the plenaries are documented at: https://github.com/WebOfTrustInfo/rwot7/tree/master/event-documents/plenaries

At end of 3 days of #RebootingWebOfTrust we have collaboratively written to first draft 15 papers on the future of self-sovereign digital identity: https://github.com/WebOfTrustInfo/rwot7/tree/master/draft-documents

We used the design workshop format for seven #RebootingWebOfTrust events. The last generated 15 whitepapers driving the future of decentralized identity in just days. Huge profit to intellectual commons! https://github.com/WebOfTrustInfo/rwot7/tree/master/draft-documents

I have mixed feelings about this. On on hand the students are getting some value for offering their personal information + attention & consent is explicit. But I’m increasingly uncomfortable with PI as a property right as PI can also abuse human rights. https://www.npr.org/sections/thesalt/2018/09/29/643386327/no-cash-needed-at-this-cafe-students-pay-the-tab-with-their-personal-data

So far the incident response & transparency that Facebook has offered for this 50M account breach is commendable, however the fundamental problem is that it is a centralized identity architecture that serves as a huge honeypot. #Decentralize! https://newsroom.fb.com/news/2018/09/security-update/

Another business model I’m increasingly having mixed feelings about: insurance companies using fitness tracker data for discounts. Lots of personal & even broad economic possibilities for better health, but also huge opportunities for misuse. ZK-proofs? https://www.vox.com/the-goods/2018/9/20/17883720/fitbit-john-hancock-interactive-life-insurance

A challenge is that many of those works related to social choice theory are not very integrated & more recent ideas that add to, revisit, or are adjacent to but are not traditional social science/economic, have difficultly speaking to that mixed language. Very interdisciplinary!

I am hoping that as a community we can prioritize a time to meet in order to have a design workshop (a collaborative process I’ve used successfully in digital identity community) to bring together people to synthesize these interdisciplinary approaches and create something new.

It doesn’t scale, as at every nodal size how human trust functions is different in the human brain. http://www.lifewithalacrity.com/2008/09/group-threshold.html

This week’s #RebootingWebOfTrust design workshop (our 7th) we did 15 whitepapers to first draft in 3 days. If we can get the right mix of people we can do same. https://github.com/WebOfTrustInfo/rwot7/tree/master/draft-documents

Ah, but information gleaned this way may be considered less legally toxic as it was given with explicit “consent” & defined “consideration” allowing it to pass GDPR-like tests and contract law challenges in many jurisdictions.

Part of the problem is that personal information is often considered a property, thus can be bought & sold. However, like you can’t sell your organs or yourself into slavery, I think there should be limits on what we allow others to have power over others. http://www.lifewithalacrity.com/2015/04/the-four-kinds-of-privacy.html

