upvote
That's self sovereign identity. But you still need someones that can issue those verifiable credentials, and we (as a global society) can't decide who that should be in the web of trust? Our banks? Governments? Schools? Doctors at time of birth?

Arguably, that's the only way forward. SSI is also nice because you get to fully control what you share and don't share (e.g., age verification, you get to only share "I am over 21" and no other information).

Passkeys were (are?) supposed to be just a password replacement though. That services are using them to replace a username AND a password AND 2FA is a problem that's turning the device into your identity, instead of keeping the identity as three parts (What you know, what you have, who you are (biometrics)). Now we've just turned the "something you have" into the entire identity stack.

reply
How do we verify that you are you? It can't be linked to fingerprints, iris scans, or DNA, as those are trivially leaked, impossible to change, and a privacy nightmare.

Until we find a way to securely implant a Yubikey in people's brains, it isn't going to happen.

reply