The end of the seed phrase

A persons identity is incredibly precious, but because of the way in which technology and identity have evolved, todays systems don’t treat it with the care it deserves.

May 2, 2024

A persons identity is incredibly precious, but because of the way in which technology and identity have evolved, todays systems don’t treat it with the care it deserves.

That’s not just a problem for the individual, it’s also at the root of problems like hacking, account takeovers and fraud.

The issue is very simple. We take a risk based approach to identity when identity is actually binary. In isolation, a particular use case may not feel like it warrants strong identity verification, but we have to look at the risk through the lens of the user, not the use case.

A user’s data is not just used by them with you, they use it everywhere because it is how they identify themselves to everyone. Bad actors leverage the ubiquity of an individual’s personal data, correlating legitimate and stolen data to commit crime.

A risk based approach to identity provides opportunity and creates demand for criminal activity. The fact that you don’t always know who your users are is both why you get hacked and how you get hacked.

The best identity systems are reserved (by virtue of price) for banks and governments, but they are flawed enough that money can still be stolen, or identity compromised.

At Self we do one kind of identity work — confirming the human behind every action. One that tells you who your user is when they try to do something.

We believe identity belongs to the user, and that companies shouldn’t be the arbiters or holders of a person’s identity. That’s why identity in Self is controlled by the person it relates to.

They don’t need a username, or password, they don’t need an account number. You don’t even have to know who they are for them to be able to use Self to prove they are the right human. They just need their Self.

Encrypted, but to whom?
Prime Minister Andy Burnham exchanged messages with someone impersonating Trump's chief of staff. He worked out the impersonation. The problem is that they could reach him at all. The device in a public official's pocket has no identity layer.
Authentication
Authentication is meant to establish that a person is who they say they are. In practice, the mechanism checks a credential — and adding more factors does not change what is checked. The research asks how authentication can check the person, not just the credential.
Digital signatures
Digital signatures inherited the name from wet ink but the mechanism is actually cryptography. Digital signature tiers are honest accommodations for an identity gap they cannot close. The research asks what a signature is, once the document is no longer the point.