New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

The Marketplace of trusted credentials in Web3 - Sebastian Rodriguez | Polygon

ETH Belgrade CommunitySat, Oct 7, 2023, 12:00 AM

Speaker

Sebastian Rodriguez

Transcript

um hello yep okay some people are still taking places um well first of all things to the organizers because they're being very flexible uh my flight was delayed by three hours so that's what I missed the first day right so uh quite a changing topic talking about identity now and well as you know I work for polygon the Prototype I'm representing his polygon ID I'm the product lead for polygon ID and well I hope this is this is short and sweet because I know that I'm depriving some of you from your coffee break so um why is why is identity a Hot Topic and I think it's a Hot Topic essentially we get like a new competitor every quarter that means that uh some people many people are interested in this many have said that this is like the next use case after morning right [Music] web3 is is certainly looking for that next real use case that doesn't involve money or transfers value and identity and I would say identity plus authenticity could be could be that the next use case so this is from just uh seeing a week ago somebody posted a picture of the Pentagon with an explosion generated by AI from a verified Twitter account and the stock market drop Millions like for 10 minutes or something like that right so probably was a test trying to see what is the impact that you can create with a simple AI image right and the the irony is that it was published through a verify Twitter account right what whatever verified means right so that means that when the verification of the identity is not done right it's even increasing the power of the of the effects like this right because you are you are tarnishing this with a with a layer of credibility right there are other reasons why identity is becoming a Hot Topic regulations uh a lot of them Mika is coming to EU age verifications are becoming uh the norm in many English-speaking countries but probably very soon to to other countries so like it or not uh if word tree is going to become the the layer of value for the internet is going to be regulated that's uh I think it's not a matter of if we like it or not it's going to happen so I think our position to that or our our reaction to that could be okay if it has to be if there has to be some control of an identities what is the most private uh the most the most privacy preserving way that we can implement this how is the best way the more decentralized ways that we can implement this uh and the last thing is uh reputation right this this old meme that is quite Visionary right a lot of the use cases that we're trying to implement require reputation and reputation is not what we see as repetition today thinking your own personal reputation it can be positive or negative right you cannot take it away you cannot renounce to your reputation you carry it with you wherever you go right and a lot of our financial systems our value systems social interactions are based on the fact that you have something to lose if you don't have anything to lose if you could just reset your identity in the morning and start fresh right the only reputation is positive reputation and we assume that the lack of reputation is negative reputation uh but that doesn't work that doesn't work for for many use cases and the first uh Foundation to have a permanent reputation a real reputation online is to have an identity an identity that we cannot just reset an identity that goes with us is a version of our identity online so summary for all the promises that we have here uh on this side that are all promises that we we have in hearing from for many years right in web 3 to have uh digital governance right to act as a ledger for the world to to to to regarding the content authenticity which is a new space for research right to have compliant crypto to have digital reputation to have civil proof protocols on the app for all that we need to trust our users to be humans uniques compliance well repute trustworthy right so that is why identity has become now the center uh of many debates and what if you search in the web previous page you will see that there is an identity solution popping up every every two months right A lot of people is now devoting a lot of investment and research trying to find out what is the best uh approach to that so summarizing it there are three ways or three approaches that we see in web 3 around how to solve the challenge of identity identity is nothing more than or line I mean digital identity it's nothing more than either an identifier and a set of attributes right um and I'm taking that very abstract definition the first approach the first reaction was for people to say okay nfts and if these are the attributes and of course the identifier is my ethereum address and that was validated with the with the proposal for the sold out tokens right so bound tokens tokens that cannot be transfer can can be expressed in your identity many positive ways manipulative positive things about nfts they are easy to understand they are easy to implement the word Community is is very familiar with them with the concept right but they're bad for privacy they are fixed on one chain and they are fixed on one others so the amount of things that you can say about an address publicly on a public Ledger that is going to stay there forever and ever and ever are quite limited because if you put it on chain uh it doesn't even matter if even if it's encrypted right because it's going to be there 100 years from now it's gonna still be there saying something about that artist so nfts turned out to be very good for public expressions of reputation so see or the way I want to say it seems you want to brag about right I'm a member of this now I'm a member of this team I'm an advanced developer so since that you will be exposing on the street like batches on your share right you don't care people to know that right but they're providing information about your your mothers right there and and everything you have is going to be another sign now right and over time you're gonna be saying a lot about that address and the other thing is you can just ditch that address and start a new one which uh it's against the idea of having uh um a true identity that represents you the second approach uh is what I'm calling the identity Oracle they did the theoretical approach is we are still using your ethereum address as your identifier and there is a very good reason why these two solutions are using your ethereum address is because every the app in the world when they started first app in the hello world the first thing they do is they put the button connect your wallet right so the word free community has already decided that is the authentication mechanism for good or for bad right so that's why these two approaches take that that's as an assumption right the ethereum address is the identifier now if the theory model is identifier but I don't want to use nfts I don't want to put things on chain right I will create a mechanism and there are many ways to do that right for which at the app that is given an ethereum address can talk to an oracle somewhere and answer yes or no questions about it like are you over 18 uh have you passed kyc are you a human being do you live in North Korea right things like that uh why are these yes or no answers is it has to do with the fact that the Oracle is not sitting on the device of the user is sitting somewhere and I said where I mean the cloud or blockchain right which means if you put things in the cloud or on chain you can uh use serial knowledge proofs you can use Merkel trees you can use protocols like semaphora you can use things like that right so in the end you are either using decentralized storages you're using blockchain you're using Cloud uh to to have these yes or no answers about a given address right and this is good this is a very good approach it's a solid approach and it actually solves eighty percent of the use cases that we are facing today like proof of humanity age Etc right now it's not really solving all the cases it's not solving for it's very difficult to solve proof of uniqueness with this uh it's very it's very difficult nobody has yet come with a solution to have an oracle that can share private data can host private data and share the raw information like give me your passport number or give me your hash uh your biometric hash right these things are more challenging because either you put it in a centralized server that you control and it's private but then you're going to a centralized solution right or you put it in a decentralized storage blockchain or whatever and then you cannot have this this personal data and share it uh row right so I would say it's a it's a solution it's a solution for good solution for many cases but not the complete solution uh for a compliance and and end-to-end solution that supports uh reputation also the fact that you're still using the ethereum address means that everything that you put there is telling to the world that the owner of this ethereum address is over 18 is from this country etc etc so also you need to be very careful with information on people there the last one is uh is a well-known uh model is is older than than the blockchain probably is the idea of this uh SSI or self-sovereign identity in which the credentials are owned managed and controlled by the user itself so you have verified your credentials which is a standard defined by the w3c you have them in your wallet right and you decide when you share these credentials you present the credentials in the same way you present your national ID I also user identifier it's not your ethereum address it's something called the did the centralized identifier right which is completely detached from urethane address in that way when you present credentials you are not necessarily disclosing anything about your ethereum address uh that is uh the only model of the tree that can solve for every scenario it has proven to be compliant and support every single uh every single combination of privacy and compliance the only challenge with this is as I say is not using the ethereum address it's using ID so it requires additional learning from all the actors in the ecosystem oh sorry um so what are the blockers and enablers sorry there's a typo here for a new identity in web3 right so these are the three models there is no clear winners right now the some people are using nfts because they are okay with positive reputation some people are going for the oracles because it's easier to integrate some people are exploring SSI because they want a future proof solution right so far uh nuclear witness polygon ID is positioned on the right we provide an SSI solution right with a verified credentials the IDS the full stack now the blockers the reason why this is not catching up I in our opinion is not about not only about the technology or technology approach it's about that technology is an ecosystem it's a market right that involves many actors it involves the people capable of uh issuing the the trust issuing the credentials or certifying certain things about you uh also the applications that need to verify these trust these credentials and then the clients the wallets I mean it's an ecosystem you need to put a lot of people in the same direction and everybody needs to be waiting for the same ideas and methodology this is a massive movement right so first of all yeah the market is very fragmented first you need to choose what is your model second the lack of interoperability right if you ask for credentials about your age or your kyc to one provider they may not be good for all the apps that you are interfacing with and you may need to go through the same process four of our times also if you go with one's identity solution may not be compatible with credentials from another oriented solution uh uh then there's the inertia right people are signing with metamask and that's enough right and anything that you try to put on top is is getting uh a bit of rejection by the community credentials providers are not uh startup friendly if you try to sign a contract with any of the kyc providers and you go to the onboarding process and etc etc it's not easy at all for for uh for a startup that usually is not a heavy not very strong on on the admin side and then the user experience right anything you introduce that is new is a user experience Challenge and the apps Protocols are very reluctant to add anything new to the experience that's why we are we are focusing now so we we have our product is being in the making for the last three years I think so we have a protocol that is called identity uh that has been in the making for three years it's super solid I I'm not here sorry and I know this is the Builder stage and I should be on the main stage but I'm not here to give details on the technology because the technology is super solid you can check it it's uh it was built to to be capable of supporting general elections in a country right that is the level of privacy and sophistication of the technology but yet we see we think that is not the main reason why identity is not taking up in in group three uh one of the things we need to address first is this availability of credentials this interoperability and the convenience of adding credentials to your applications right and that's why working now in the concept of the marketplace of becoming a Marketplace of trusted credentials right we want to create liquidity of credentials in the ethereum ecosystem and that means having providers already integrated uh there can be Plug and Play so you basically go there find your the provider of the credentials that you need if you want to check uh kyc you want to check age you want to check location you want to check whatever from your users any attestation you need to be made for your users you just check the provider uh integrate one SDK and then you're free if you want to move to another provider you just put into a different direction right you decide which credentials you are set but you don't need to uh speak different languages for all these providers right we are also developing services and tools to put all these providers uh in common on certain number of Standards right uh following SMS schemas following the same rules following the same billing processes following the same payment processes right so it really feels like you are going to an Apple Store of credentials yes choosing the one you need and we take care of the rest uh these are some of the partners that we have awarded uh there are more I think this is this is not the latest version but you have a URL here where you can check all the companies that we are onboarding and here we have a clear Advantage right this is the brand we are we are quite big in the culture community and we are using that uh plain and simple right we're using that to attract Brands to our ecosystem and to onboard Partners so you don't have to so you don't have to integrate with your specific sdks uh of any of these issuers right uh we're also integrating wallets and system integrators in case there is a big integration uh and somebody can support it right and this ecosystem is growing you can uh some of them are are offering paid credentials like ahkyc Humanity Etc some of them are offering online reputation batches uh and I see that you can also use so uh you can check it yourself this is here is the code we provide three things if you are a source of trust if you can say something of valuable users right you can be an issuer of credentials maybe you already have information about the user so you want to give the users that information in a way they can use it somewhere else right maybe you are a game and you want to give them credentials about some achievements that they can use in some somewhere else maybe um your uh your uh an exchange and you already have passed kyc for the user and you want to give that to the user so he can reuse the kyc that you have done for them in other places as an additional value in that case you are an issuer we have a self-hosted uh API where it provides everything uh for the issue for the issues of credentials if you're an app we provide the sdks for the verification and also a query language so you can build your query like prove me this and this and share this data etc etc from your wallet uh that turns into a QR code and then uh everything all the magic happens in the wallet right we also provide on chain verification which is one of the key features or the differential features of our of our solution right because verify credentials have this weak point compared to nfts that they cannot be verified on chain and we provide uh on-chain verification with zero knowledge proofs right uh and the last thing is if you are willing to develop your own wallet or uh your web wallet or JavaScript or the App application we provide both a wallet SDK and a JavaScript SDK for the client right to store the credentials to offer the credentials and it has the the the the good thing is it generates we are the only solution capable of generating zero knowledge proofs on the client right so zero knowledge proofs are generating on the device on the phone right in real time and answering to a to a dynamic query which is quite quite Innovative if you think about it right use super easy use case to understand what I'm talking about is uh you can collect the credential somewhere and then you can present the proof of credential directly to a Smart contract on chain to get an airdrop right or a hackathon you can you can get paid the Bounty uh if you present your kyc credential directly to a Smart contract in a trustless way so these are two use cases just to put everything together so and I think I'm I'm gonna finish it here I have tried to go fast because uh I want to give you some time for question also for for coffee if it's still there is time uh but just just the last uh idea I want to share is that everything has moved online but trust right uh if you think about it uh the value the the monetary value the on the on the assets uh we're trying to move that on chain our social life social interactions have move on change a lot of processing Dynamics are now online but no trust right we haven't managed to find a way to create real trust in the digital world and this is this is where we are positioned on our our product and our valuable position so thank you very much and if there are any questions [Applause] do we have any questions okay I'll start here hi oh this is okay hi um I think what's missing is the killer app so uh what in your opinion would be something or maybe it's already something that me as a user right gives me the the reason to go through is all kyc ml song and dance and what can I do with my KY seed wallet that's so amazing um that I want to do it okay yeah excellent question okay first of all nobody no nobody likes kyc kyc is uh so but the thing is we have vitamins and painkillers right vitamins are things that you want to take in a positive way there are nice things to have there are delighters right and that that's that is where you find your killer app now the painkiller systems in that you don't you don't have a you have an option right kyc is going to be mandatory and then people are going to look for the best and less painful way to do it right so I will say long term the the less pay less painful way to do kyc is in a private manner there are so proof of kyc instead of kyc right and the second is reusable kyc that is the dream but that is that means to put a lot of actors uh thinking in the same direction it's a long journey yes unify schemas unified standards on board so this is a long path to the reusable kyc right technology is not enough this is a this is a market effort right now is there anything before that I think so I think there is a killer app that we can find sooner and the concept is super simple is signing Google without Google right so that is the experience people are willing to accept people will are in our daily lives we click a button we do all the onboarding into an app we don't need to fill any more forms it's just super simple and then if the application wants access from us wants to know things about data access to our resources there is a consent right these two steps and only these two steps are where users are willing to accept right right now the only ones that can provide that level of experience are Google Facebook and apple right on all these social logins right so having a social login without any company behind it is a neutral social login right that I really control and own I think that is the the first killer lab that we can build okay thanks we had one more question okay thank you Sebastian for the wonderful message at the end uh a nice talk but first thank you I wanted to ask um what are your thoughts on letting companies and organizations slowly adopt these technology for example am I at an advantage as a company if I provide open Protocols of authentication authorization to my users are you supporting something like oidc or oauth 2.0 or something like that and can it speed up the adoption what are your thoughts yeah thank you for the question very good um actually you ask two or three questions two first first uh for us with an SSI product verifier credentials and the ideas it will be much easier guys much easier to sell our product to the corporate world that's actually here I'm saying that with some reason because I've been working in the corporate world for many years in my life right so all these things are super easy when you control the environment so you create your own company wallet you issue the credentials by yourself and then you control the verifiers these are close ecosystems it's super easy so yes much easier for a company an NGO a government any local organization that controls all the all the ecosystem right I think has a very good advantages of offering this now that depends on how much people care about decentralization and privacy we tend to think that these are things meaningful by themselves and and for for companies these are just features right and and but more and more we see we see more attraction so yes it would be much easier for uh for a corporate the second question about oauth and open ID we have something different in ethereum world right in the making our equivalent to uh all out in the web 3 world uh sorry no to open ID could be signing with ethereum and the equivalent to out is an EIP that still in the in in the draft right is Recaps we're gonna it's gonna manage the the granular authentication of resources after you have signing with ethereum do I like this no because I think we made a poor choice and now we are going with it all the way down right we choose that our identity is going to be our wallet right our ethereum address and I think that is a terrible decision right but the community already has made it right so I think we need to provide that signing with a neutral uh Oracle killer app on the things that the community is already doing right we cannot base our product until everyone every day that you made the wrong decision uh and later maybe we we can uh get these standards closer to the IDS and the coupling from from the ethereum address thank you do we have any more questions okay I see yeah thank you for the talk yeah uh what do you think about uh like not only polygon like how polygon ID do you have any plans or ideas about moving to other blockchains like in like multi-chain ideas like this yes yes certainly uh that's a question we get very often because uh in all honesty I wouldn't trust the an identity solution that only works in a chain right that's a massive weak uh weakness in our product right now right but it's not an intended weakness we advertise our product always as evm compatible right and it is easy and compatible so our limit our scope is ethereum right we don't have plans to go to bitcoin or anything like that our world is ethereum now every time somebody asks but do you work for for other blockchains we say look we are EVN compatible right now we are not providing any support anyone can copy our contracts so all our code is open source we have changed now for MIT and Apache so you can even build commercial products on top of them right so it's actually we know that companies now are writing manuals on how to move to other change boiling already right and this is not something we want to stop we are not supporting it right but we we really want to stop now long term the what is happening is we are working on our monetization model because you wouldn't trust an identity solution that is in one chain but you also wouldn't trust analytic solution that is not sustainable right so we're working on a on a monetization mechanism and this Marketplace idea is is our monetization strategy right in the end we want that you can use our credentials on any evm compatible chain as long as you purchase your credentials on polygon right so you buy it here you use it anywhere that is our vision thank you

Automatic transcript — names and jargon may be misspelled.