0:00 Phil Windley | Digital Identity Needs a Legal Foundation | KERI Conference 2026
0:04 Okay, I'm going to start
0:07 since we're over time already. I'm
0:12 glad to be here today.
0:15 Title of my talk, as you can see, is
0:17 “Digital Identity Needs a Legal
0:19 Foundation”. So if you were at SEDI
0:22 summit
0:24 with the first two days of the week,
0:27 this is related to the things I said
0:29 there and just kind of goes into a
0:32 little bit more detail on how the legal
0:34 foundation actually helps us out. So we
0:37 spent a lot of time talking about
0:39 the cryptography and key
0:41 management and all of those things.
0:44 But I think the hardest part of digital
0:48 identity is actually
0:51 not the technical things but legal and
0:56 institutional. I spent a lot of
0:59 time talking about governance and
1:04 sometimes it's can be kind of
1:06 boring but ultimately I think it's what
1:08 gives us the foundation for making all
1:10 of this work. So, think about where
1:13 we're at. We've got decentralized key
1:16 management, authentic chained credentials,
1:19 Serialization formats,
1:23 some implementations, open- source code.
1:27 So, the technical foundations
1:30 are largely there. That doesn't mean
1:32 they're done. Doesn't mean they can't be
1:34 improved, but we've made real progress.
1:37 We also have things that we're still
1:40 working on like tooling and ecosystem
1:42 and developer experience and all of
1:45 those things that make it work.
1:48 But we need to get adoption. And in
1:50 order to get adoption,
1:52 we have to
1:56 get rid of some of the fundamental
1:57 blockers. Now, I'm going to talk about a
1:59 couple of them today. Not necessarily
2:02 all of them. I mean because
2:04 there's no end to blockers when you're
2:06 trying to do something this big. But
2:08 there's a couple of them that I think we
2:10 can help solve. So Sankarshan
2:16 How to say his name Mukhopadhyay I think
2:20 is how you say his last name. I haven't
2:22 heard it said so I'll say it that way.
2:24 Recently wrote a book about what he
2:26 called the a book a paper what he called
2:28 the proof gap. And for him, the proof https://thetrustgraph.substack.com/p/the-proof-gap
2:31 gap was the idea that we still rely
2:35 largely on centralized institutions to
2:39 be able to prove things about ourselves.
2:42 So, our education, employment, whatever
2:45 licenses we have benefits
2:47 we're entitled to, all of those things.
2:50 When proof is needed, we can't generally
2:53 present it directly, especially
2:55 digitally in a way that somebody else
2:58 can easily verify. So even worse, I
3:03 mean, if we lose that proof, we have to
3:05 essentially go back to those
3:07 institutions one at a time and confirm
3:10 something about ourselves, right? So
3:12 that could be a real problem.
3:16 Back 50 years ago when
3:18 everything was based on paper and kept
3:20 in filing cabinets, that might have made
3:22 sense because it was really all you
3:23 could do. But I think everybody in this
3:25 room acknowledges that we can do better
3:28 than that in a digital world and we
3:30 should do better than that, not just
3:32 take that old paper filing cabinet model
3:34 and move it forward.
3:36 So sometimes people think of the proof gap
3:40 as a technical problem and it certainly
3:43 is that. There are technical problems
3:45 with moving this centralized filing
3:48 cabinet model into the digital world and
3:51 trying to decentralize it and create
3:53 something that's better.
3:57 But I think we can ask
4:01 ourselves about the problem of
4:03 governance.
4:08 There are lots of ways that we have
4:09 worked out how to
4:13 transfer trust
4:16 in the physical world, right?
4:21 One of those is very familiar to
4:23 everybody and that is credit cards.
4:30 60 years ago,
4:33 we didn't have this problem because we
4:35 didn't have credit cards really at all,
4:37 right? There were bank cards and
4:41 maybe had a card from your department
4:43 store, right? I remember people had
4:44 Sears cards that you could use at Sears
4:47 and nowhere else, right? So they were
4:49 all centralized, single domain and Visa
4:53 first and then others followed came up
4:56 with this idea that we could have a
5:00 coalition of banks put together ways
5:03 that they can work together. So this
5:05 involved technology, how are we going to
5:08 technically transfer information? It
5:10 involved rules and processes. It
5:13 involved legal agreements. Involved all
5:16 of this. And collectively we call that
5:18 thing a trust framework, right? All of
5:21 those technical and legal and regulatory
5:24 rules that make all of that work. But
5:27 even today if you're a merchant,
5:31 you've got multiple ones of these that
5:33 you have to interact with. Now, it turns
5:35 out somebody saw that problem and there
5:37 are all kinds of companies. There's
5:39 actually between this guy and those
5:41 guys, there's like four layers of
5:43 companies that make this all work. In
5:46 order to make it easy for him and for
5:50 you when you go in, right? He doesn't
5:52 have to have six different terminals and
5:54 all of that because somebody's solved
5:56 that problem. But still, it's a problem.
5:59 Now, imagine what happens when we've got
6:01 not five different banking system or
6:05 credit card systems. We have thousands
6:08 of different credentials. Now we're
6:10 trying to navigate the sea
6:14 of islands where each of these is a
6:16 separate trust framework with their own
6:18 rules, their own governance. Maybe they
6:21 share some technical underpinnings
6:23 at least we could hope
6:25 for that. But it's still a problem. If
6:28 every category of credentials requires
6:30 its own private trust framework and
6:33 every verifier has to somehow be inside
6:37 each of those trust frameworks, it's a
6:39 nightmare, right? Instead of four layers
6:42 between the merchant and the credit card
6:43 companies, we'll have a hundred layers
6:45 between you and all of the
6:48 different things that you might need to
6:50 verify in your life. Now, private
6:53 governance can solve some of these
6:56 problems, right? And we've seen lots of
6:58 efforts over the years. IRA is one of
7:01 the most recent that tries to
7:04 create a coalition of
7:08 related or like-minded maybe
7:10 organizations who can come together and
7:13 create a trust framework that is
7:15 interoperable and I think
7:18 they all kind of have this vision of
7:20 we'll just get big enough that
7:22 we'll solve this problem. It won't be a
7:24 problem because we'll just get big
7:25 enough that everybody will be part of us
7:27 but Visa is not part of
7:30 Mastercard and they never will be.
7:32 And that's always going to be a problem.
7:35 So a different way to solve this problem
7:39 is to have something underneath all and
7:43 connect them. Okay, but that's just one
7:46 problem. There's another problem. I
7:47 talked about this in my talk on
7:50 Monday and that is an economic problem.
7:53 So in the mid 1990s,
7:56 Netscape had essentially solved the
7:59 digital identity problem for at least
8:01 the web. I mean, they had
8:04 pretty good ideas, right? We'll have
8:08 servers that will have certificates and
8:12 we'll put certificates in browsers
8:15 and your browser certificate will
8:18 identify you. We'll proof your identity
8:21 with these certificates. I mean, in
8:23 this day and age where you can
8:26 essentially get server certificates for
8:28 free, you may not remember, but back in
8:32 the day, certificates were really
8:34 expensive because they were all proofed.
8:37 Right now, they basically just link a
8:40 domain name to a key. That's all they
8:42 do. But if you want a real proofed
8:45 certificate, they cost money. Not only
8:47 because it costs money to proof you, but
8:49 because the company is putting
8:50 themselves out there and saying “this
8:53 information is correct”. So, they're
8:55 liable. So, they cost money.
8:58 Turns out, people were not
9:00 willing to pay money to shop and to bank
9:02 and all of those things. They wanted it
9:04 all to be free. So
9:08 we standardized on "Servers will have
9:11 certificates and people will have
9:13 passwords" and just kind of waved our
9:16 hands and hoped the problem would go
9:17 away because there was money to be made.
9:21 So here's the two problems. How
9:23 we scale trust. How do we create
9:25 trust frameworks that are more
9:28 universal? And second, who's going to
9:31 pay for this. Who's proofing the
9:33 person using what authority, what's the
9:36 legal standing, all of those questions.
9:43 This is where I think SEDI can help us
9:45 with both of these problems and
9:48 I'll talk about them in some detail.
9:51 As far as scaling trust, SEDI
9:56 doesn't provide any kind of universal
9:59 trust framework. That's not the answer.
10:01 What SEDI provides instead is a
10:04 foundation that trust frameworks can sit
10:07 on. So we have something that is
10:10 firm underneath, a firm legal foundation
10:13 for all of these other things that are
10:14 going to happen. The second help that
10:18 SEDI can provide is on the economic
10:20 problem because turns out that the state
10:26 already has lots of infrastructure
10:30 for doing this. They already
10:32 proof you, part of if
10:34 you look at your driver's license, we
10:36 have a couple of people from Europe here
10:38 so they may not be familiar with
10:40 this idea but if you look at your
10:41 driver's license which is the only thing
10:43 we have to prove who we are, there's a
10:45 little star on it. You know what that
10:46 star means?
10:49 “REAL ID”.
10:50 It means the state proofed your identity.
10:54 So this was started in 2005
10:59 when… earlier than that, maybe 2002…
11:03 It was right after 911.
11:06 It happened
11:08 before 911, because I remember I was CIO
11:10 when they started talking about this.
11:12 This was early 2000s, right? So,
11:15 proofing your identity. And at the time,
11:16 the motor vehicle division, the driver's
11:18 license division said, "We don't want
11:21 anything to do with identity. We're not
11:23 an identity
11:25 provider. This is not us." Well, let's
11:28 see how that worked out for them. So,
11:30 anyway, you have the old star. They
11:31 already proofed your identity.
11:34 So, let's talk for a minute. I think
11:36 most people at this point probably have
11:38 an idea of what SEDI is, but let's just
11:40 make sure that we're all on the same
11:41 page. SEDI doesn't give you
11:44 an identity. In fact, the SEDI
11:47 legislation specifically says:
11:50 "An individual possesses an identity innate
11:54 to the individual's existence and
11:56 independent of the state. Which identity
11:59 is fundamental and inalienable." SEDI
12:02 doesn't give you an identity. They're
12:04 not an identity provider, right? That's
12:06 a nice term. Instead, what it is, you
12:11 create your identifier or identifiers.
12:16 The state proofs specific attributes
12:19 about you,
12:21 then links those attributes to you
12:25 in a cryptographic way, not to you,
12:28 to this identifier (that you
12:30 control). In a cryptographic way.
12:32 So, you can kind of think of this like a
12:34 notary, right? The state is endorsing
12:37 your identity, not giving you an
12:41 identity. They're just saying, "Yeah,
12:44 this identifier, we looked at the person
12:47 who controls it, and that really is the
12:49 name and the birthday and the address
12:51 and whatever other attributes might be
12:54 part of your SEDI."
12:56 So SEDI not just one credential.
13:02 Like I said, you create an identifier
13:05 (or identifiers),
13:08 and then SEDI
13:11 is a credential which links those
13:17 attributes (that the state has proofed
13:20 and endorsed) to that identifier.
13:25 Now there could be other government
13:27 credentials that sit on top of that.
13:30 Things like driver's licenses. We heard
13:32 Joe talk about offhighway vehicle
13:35 operator licenses, fishing licenses.
13:39 States are veridible credential
13:41 factories. They just love giving
13:44 credentials to people for different
13:46 things, right? So, states have lots of
13:49 them. Now, some of these will involve
13:52 guardianship, things like birth
13:53 certificates and school records, and the
13:55 statute includes that idea.
13:58 Others will be just things that you get.
14:00 And, like I said, I've got six
14:02 up here, but there probably a thousand
14:04 of them that states have. Most of us
14:07 don't care about most of them.
14:09 But also, other institutions can give
14:12 you credentials. So, you could use your
14:15 SEDI to prove who you are when you go to
14:18 the bank to get a credential from your
14:21 bank. Or you could use your SEDI to
14:23 prove who you are when you're
14:25 registering for school and you would get
14:27 a school ID. So all of these other
14:29 credentials are essentially resting on
14:31 this foundation that SEDI has provided.
14:34 And you can even issue your own
14:36 credentials. You may not imagine why
14:40 that would be interesting now but I mean
14:42 with personal agents, AI agents
14:45 coming along this could be a lot more
14:47 interesting.
14:51 But it's not just people.
14:54 So there's also organizations. Now this
14:57 is not SEDI. This is different than SEDI
15:00 but it's related to SEDI and important
15:02 for what we're talking about. So,
15:05 organizations already have firm legal
15:07 foundations in the sense that
15:10 you can register a business and the
15:13 commerce department gives you a
15:15 registration number and the IRS gives
15:18 you an EIN and all of these things that
15:20 come along with being an organization.
15:22 We don't care as much about the
15:24 organizations creating and controlling
15:26 their own identifiers, but they
15:29 will, right?
15:33 State Department of Commerce generally
15:35 in the United States at least is who is
15:37 responsible for endorsing that
15:41 so you could imagine a SEDI-like
15:44 credential or it might just be their
15:46 business registration but anyway
15:50 it's analogous to the SEDI.
15:53 Organizations like GLEIF
15:56 are indispensable for businesses and
16:00 other organizations who need some sort
16:03 of global reach.
16:08 I got an LEI just because I wanted to
16:11 see how it worked. I've never ever used
16:13 it for anything, for my business.
16:16 But that's important.
16:18 Because there are some things like
16:20 government credentials and banking
16:21 credentials, business licenses that
16:24 would just depend on whatever
16:25 organizational identity you have,
16:27 whatever identity or credential
16:30 the organization has from the
16:32 Department of Commerce, but many might
16:35 require this global interaction.
16:38 Local restaurant might not ever need an
16:41 LEI and all of the things that go with
16:43 that, but a bank might.
16:47 Now,
16:49 let's talk for a second about the legal
16:53 underpinnings of SEDI because this is
16:55 important. I mean first of all SEDI
16:57 includes a bill of rights. I read you
16:59 the statement that it says about your
17:01 identity belonging to you and being
17:03 inalienable.
17:06 These are legal rights, not terms of
17:09 service. This is not a
17:10 click-through contract that you don't
17:12 read. And, if you want to
17:15 enforce whatever small rights they might
17:18 have left you in this 60page document,
17:20 you have to go to court. These are
17:22 things that are in
17:24 statute. They're in law. It also
17:27 includes selective disclosure. So the
17:29 idea that you don't have to disclose
17:33 everything in a credential
17:35 or in your SEDI credential in order to
17:38 use it. You can just disclose the parts
17:41 that is necessary. Requires that the
17:43 system be built on open standards.
17:46 That it's not a proprietary system MDL.
17:53 So, no vendor lock-in. Anyone can
17:57 build a conformant
17:59 wallet verifier, whatever. Speaking of
18:02 wallets, it mandates a choice of
18:04 wallets, right? So, there's not just one
18:06 app that the state gives you. And if you
18:09 don't have that state app, you don't
18:10 have a SEDI. You can choose different
18:13 wallet providers. You can put your SEDI
18:15 in any of those, move it between them,
18:18 whatever. It includes a
18:22 duty of loyalty which is like a
18:24 fiduciary requirement for identity
18:29 data which is a first. This is
18:32 revolutionary in the world of digital
18:34 identity.
18:36 And finally, like I mentioned earlier,
18:39 it supports the idea, recognizes that
18:42 many people are
18:46 wards of a guardian, and therefore the
18:50 guardian has to have the rights and the
18:52 abilities to carry out
18:58 functions,
19:00 operations on their behalf. I don't know
19:02 what the right word is. Carry out what?
19:04 What are they doing? Acting on their
19:06 behalf. There we go. Acting. That's the
19:08 word I was looking for. Nice simple
19:09 word, not carry out duties. Okay. So,
19:13 these are all part of the statute and
19:15 important to why SEDI creates this kind
19:19 of legal foundation.
19:23 Now,
19:25 as I mentioned earlier,
19:28 the problem in this proof gap is that
19:31 when institutions make errors,
19:34 you basically are left to navigate the
19:36 correction process all on your own. Now,
19:40 SEDI doesn't mandate that
19:43 every institution has to do things a
19:46 certain way, but it does provide you
19:48 with a legal foundation. And it does say
19:51 that you have enforcable rights
19:56 related to your SEDI. So you have the
19:58 right to obtain SEDI credentials. You
20:02 have the right to have its attributes
20:04 amended as they change, or need
20:08 correction. You have protections against
20:11 arbitrary revocation. There are only
20:13 certain circumstances where this can be
20:15 revoked.
20:18 There's a complaint, an
20:20 enforcement mechanism for how you can
20:23 deal with problems that come up and
20:26 that includes both the digital…
20:29 what's it called? A digital privacy
20:31 ombudsman and the attorney general. Yeah.
20:34 There are both of those that
20:37 give you the ability to seek redress if
20:40 something happens. So yeah…
20:42 – Just real quick, but it does not
20:44 include a private right of action. The
20:47 attorney general has to act on your
20:50 behalf.
20:50 –– Yeah, we tried to get that in there, but
20:52 they decided that was reach too far.
20:54 Reach too far. Yeah. So,
21:00 these aren't just like consent
21:03 form click-through consent forms and
21:05 support calls that you make.
21:08 These are legal remedies that
21:10 you have the right to …
21:13 They are legal remedies you have the right to
21:15 access if these things will happen.
21:18 Now…
21:20 like I said earlier this doesn't mean
21:22 SEDI doesn't
21:24 replace all of these trust frameworks
21:27 that exist. I spent my career largely
21:31 in academia.
21:34 Academics is going to have trust
21:36 frameworks about what an accredited
21:38 institution is for example.
21:42 Visa is still going to exist as a trust
21:44 framework for how
21:46 money gets transferred inside their
21:48 network. Those are all still going to
21:50 exist. But what does change is the idea
21:55 that they can sit on top of this
21:59 legal foundation. They can have
22:04 attributes that they know, someone they
22:07 trust, proofed.
22:11 Now along those lines, I want to talk
22:14 about two different ways of establishing
22:17 trust. This is a conversation I had with
22:19 Sam, at Smoking Apple six weeks ago,
22:24 or so, right? Because I had just
22:26 written a blog post about reputation for
22:29 agents. And how all that
22:32 can work. But it's equally important
22:34 here. So there are two different
22:35 ways of establishing trust.
22:40 One is by observation.
22:44 You look at someone's behavior
22:46 and you say, "Sam seems like a nice guy.
22:49 I guess I'll get to know him a
22:51 little better”, and then you have
22:53 more interactions and you build
22:56 up that trust. The second one, which I'm
22:58 going to talk about first, is
23:02 reputation by reference and the reason
23:04 I'm going to talk about it first is
23:05 because it's essentially how we
23:06 bootstrap things. So the top of
23:09 this have a diploma, so if you
23:12 want to know things about me related to
23:15 my education I can give you a diploma.
23:18 That is essentially reputation by
23:21 reference. Some institution is saying
23:25 that they did specific things and are
23:29 vouching for the fact that I met their
23:32 standards with respect to this course of
23:35 study. But who are they?
23:39 And does this really belong to me? And
23:43 what standards are they actually holding
23:46 me to? Now, if I tell you I have a PhD
23:50 from the University of California at
23:51 Davis, most people would say, "Oh,
23:53 University of California. I know that
23:56 school. I guess that's okay." But
23:58 if I tell you I have a bachelor's degree
24:01 from Norda,
24:03 whatever, what is that thing called?
24:05 Norda
24:06 Medical Thing. You guys know? Down in
24:09 Provo. Anyway,
24:12 are they good? Are they acceptable? Or
24:14 is that a good institution? I honestly
24:18 don't know. But who does? Well, the way
24:22 you do it, is this diploma can be a
24:26 credential
24:27 and it can be chained to my SEDI
24:31 credential which now means that I can
24:34 prove that this diploma was actually
24:37 linked to me or given to me. But
24:40 it also can be chained to the
24:43 university's credentials and
24:45 identifiers. So they probably have an
24:49 accreditation credential or should have
24:51 one that came from their accrediting
24:53 body. And there's not just one, right?
24:55 So there would be an accrediting body
24:57 for the university. There would be an
24:59 accrediting body for the specific degree
25:01 program I'm in. All of those… I mean
25:03 there might be dozens of these out here
25:05 that the university has.
25:08 You can also check to see is
25:11 this a legal business? Is it even
25:13 recognized as a business? So
25:17 that would be your commerce department
25:19 or GLEIF vLEI
25:22 credential.
25:23 And importantly when I present this
25:26 diploma as a credential
25:29 all of this can be checked automatically,
25:32 these chains can be followed. We
25:34 can check all of the credentials and
25:37 you can get a green light on your
25:38 system that tells you: yes
25:42 this credential is issued to
25:45 this person, it came from this
25:48 institution, that institution is
25:50 accredited by this body and this body
25:53 and this body and it's organized in the
25:55 state of Utah and all of the things that
25:58 you might want to know about it.
26:01 So that's reputation by reference
26:04 and
26:06 SEDI provides a nice foundation for
26:08 that, as do the organizational
26:10 credentials that we talked about.
26:13 There's another kind of reputation
26:16 that I mentioned and that's reputation
26:18 by behavior. Now, in the physical world,
26:20 we just interact with each other,
26:22 and that's kind of how we figure out
26:24 whether or not
26:27 we like this person. We trust them,
26:30 right? The fact that I'm going to let
26:32 you fix my plumbing doesn't mean I'm
26:34 going to let you babysit my kids, right?
26:36 So, there's different domains of
26:37 behavior that we that we look for.
26:40 We use reputation by reference to
26:43 essentially bootstrap this. I needed
26:45 someone to come in and fix an oven at a
26:48 at a rental property I have.
26:51 I didn't know anyone, so I just used
26:54 reputation by reference, right? I looked
26:56 at reviews online to see, okay, they've
26:59 got a pretty good thing. Yeah, Timothy…
27:02 – Isn't reputation by reference also an
27:05 accumulation of behaviors?
27:09 It is!, but it's at a distance.
27:13 So, we go back to this.
27:16 All of these could be many layers
27:19 away from the actual thing that I give
27:21 you. So there are accumulated
27:24 behaviors that lead to that diploma. But
27:27 it's not me who watched you
27:30 complete the degree. It's indirect. It's
27:33 the university who watched you complete
27:36 the degree and you're believing the
27:38 university. So there's an indirectness,
27:41 not a direct link. – But either way, the
27:44 quality of reputation
27:46 can't be separated from an
27:48 accumulation of behaviors over time.
27:50 Correct.
27:51 – That's true.
27:52 – And so if it's a good restaurant, it's
27:54 done well. It's had good behaviors
27:57 which got that reputation. And what
27:59 you're doing is you're collapsing the
28:00 history because it's so well known. I'm
28:02 going to collapse the history and just
28:04 say I just need to tell you the name
28:06 of the organization.
28:09 – In reputation you explicitly
28:11 trust the reputer. If you're observing
28:15 the direct behavior, the only person
28:17 you're trusting is yourself. So, the
28:19 verifier doesn't have to trust anybody.
28:22 If they truly do reputation by behavior,
28:24 they can verify all of…
28:27 Here's a different way of
28:29 thinking about it.
28:32 Trust always,
28:35 always requires vulnerability.
28:40 Trust requires vulnerability.
28:44 If you aren't vulnerable,
28:48 you don't have to trust.
28:50 So the question here is, am I trusting
28:55 me? I've eaten at that restaurant
28:57 before and it was pretty good. Or
28:59 am I trusting the reviewers, which is an
29:02 accumulation of behavior, but I'm
29:04 trusting someone else, in one case I'm
29:07 more vulnerable to mistakes than I
29:09 am any other right because it's indirect
29:12 rather than direct. That's the difference.
29:13 – You're trusting a third party's opinion
29:15 of the reputation versus your own.
29:17 – That's right. It's not whether
29:19 it's based on behavior, it's
29:21 whether it's indirect or direct,
29:24 so a different dimension, but yeah.
29:33 Right now, the way reputation by behavior
29:37 works, one example of that is credit
29:38 bureaus. So credit bureaus
29:41 accumulate
29:44 all of your transactions and whether you
29:46 pay your bills on time and whether you
29:48 were late and all of those things,
29:50 right?
29:51 And they use some algorithm to determine
29:56 a credit score which is then paid for. I
29:59 mean other places other banks or
30:02 credit card issuers or
30:05 employers and others can then pay for
30:07 that credit score and get that for you.
30:10 So that's one way that we do
30:14 behavior. Different way is, say every
30:19 time I have a transaction with company X
30:21 or company Y,
30:23 I get a receipt that I paid on time, all
30:28 of these things. Now, this may not
30:30 matter as much for individuals as it
30:31 does for organizations. I mean you can
30:33 see the organizations could really
30:35 benefit from something like this because
30:37 it's big, lots of money but anyway you
30:39 get these as credentials and now you can
30:41 prove to other people in combination or
30:44 apart whether or not you have behaved
30:48 properly. Now I have to say there's one
30:50 big problem here.
30:54 I can admit bad behavior. So, doesn't
30:58 mean that these things are ever
31:00 going to go away. I mean, I think
31:01 there's always room for things that
31:05 are looking for bad behavior. Yeah.
31:09 – One thing though that the
31:11 decentralized model allows is that the
31:15 verifier can pick their own algorithm.
31:18 If I go to get a credit score, there's
31:20 like five algorithms.
31:22 And I was
31:24 going to mention that this model allows
31:27 for a marketplace of algorithms.
31:29 And for transparency in algorithms.
31:32 Somebody might say, "Oh, yeah.
31:33 Well, we use this algorithm for how we
31:35 do how you do scoring." Yeah.
31:37 – I don't know if you were talking about
31:39 it, but you said at the bottom in
31:41 one case, you don't own your data. You
31:43 do own your data.
31:44 And I'm gonna say that this is
31:48 the sort of issue, legally, that is going
31:52 to slow us down dramatically because if
31:54 you look at what the Supreme Court has
31:57 always said, it's that no one owns
32:00 facts. Okay, data is facts. You might
32:03 own the database that the facts reside
32:05 in, but no one owns the underlying
32:07 facts. So the solution to that is to
32:11 treat those facts as an unownable
32:14 commons. Okay? And like all commons,
32:18 navigable waters or the air we breathe,
32:21 someone has to be responsible. So going
32:23 back to the fiduciary duty of loyalty
32:25 and other fiduciary duties, you are the
32:28 best candidate to be the trustee over
32:31 your facts because you're more
32:33 interested in their accuracy.
32:35 – I care about them.
32:36 – Right. And the government has
32:38 a secondary fiduciary duty to make
32:41 certain that your rights in those facts
32:45 aren't abused.
32:47 But the point there is I think that's
32:49 what's going to slow us down because if
32:50 you look at these 80page agreements
32:52 where you just click “I agree”, none of
32:55 them say “you own the data and you're
32:57 giving us ownership”. They all say “you
33:00 transfer whatever rights you have and we
33:02 accept whatever rights you have” and then
33:04 the company goes out and says “we
33:05 own this”. So it's a legal fiction.
33:07 – Yeah, I probably shouldn't say
33:10 “own” there. I mean control is a better
33:12 word.
33:13 Own is a problematic word in this word
33:16 for the reasons that you have
33:18 pointed out. And in fact,
33:23 if I'm in a transaction with someone, we
33:26 both are parties to that transaction
33:30 and we both could have a credential [inaudible]
33:33 to that transaction and we both control
33:37 that. And of course, that's just
33:39 two-party. It could be multi-party. So,
33:41 so yeah, it's about you have access
33:44 to and can control who you share it
33:47 with,
33:47 right? – And just to your point very
33:49 quickly about transactions we
33:51 always sort of say, well, the newspaper
33:54 costs a dollar. Well, if I'm buying the
33:57 newspaper, I value the newspaper more
34:00 than the dollar and the publisher values
34:04 the dollar more than the newspaper. So
34:06 otherwise, the transaction wouldn't
34:08 occur.
34:09 – Yeah.
34:11 There's cost, price, and value.
34:13 And they're not the same. Yeah.
34:16 – Even the word “your” implies ownership.
34:21 – “data about you”. Yeah.
34:26 Okay. This whole idea of
34:30 reputation has lots of implications or
34:36 ramifications for how we might
34:39 approach agentic AI and how agentic AI
34:44 works with us. I mean this talk is not
34:46 about agentic AI but I just wanted to
34:49 point out that this same foundation and
34:54 this idea of building reputation around
34:58 solid identifiers for organizations and
35:00 individuals
35:02 helps us in this space. If you want to
35:05 know details how I think about it like I
35:08 said there's a blog post.
35:15 One thing I thought of when I was doing
35:16 this actually is this idea of an
35:18 evaluator. You could imagine agents that
35:20 you employ that are evaluators. You
35:22 know, we talked about having a
35:24 marketplace of reputation evaluation
35:27 algorithms. You could imagine a
35:29 marketplace of reputation evaluation
35:31 agents who are working on your behalf
35:34 for various things. Things that
35:36 you care about and ones that you trust,
35:37 and “I'm going to use that
35:39 agent because I like the
35:41 restaurants it recommends”.
35:43 What's the technology opportunity
35:46 here? If you're building
35:50 decentralized identity infrastructure,
35:52 SEDI is an opportunity, but it's not a
35:54 guarantee.
35:59 SEDI sets out these requirements:
36:03 Open standards, decentralized
36:05 control,
36:07 that represent a high bar for how
36:10 this all has to work. And like I
36:15 said at the start of the talk,
36:18 there's the technical side of it,
36:20 which is not in any way a
36:24 small thing, but doing that at scale,
36:29 meeting the user experience requirements
36:32 that we might have, finding the right
36:34 economic models for the various parts
36:37 and pieces that have to work. Those are
36:39 all extremely difficult problems to
36:41 solve. So it's not a no-brainer
36:45 that “Oh SEDI came along good, it's all
36:48 solved” and we still have lots of work to
36:50 do. Timothy.
36:52 You've got whole talks about this.
36:54 – If you
36:56 in [inaudible]
37:01 have a legal basis in their giant
37:03 centralized digital system,
37:06 use a lot of cryptography as well
37:10 component missing
37:12 and that's the decentralized nature of
37:14 SEDI. It's trying to have [inaudible]
37:18 a legal verifiable basis but also
37:22 decentralization meaning that you can
37:24 have different vendors in different
37:26 states and different systems and they
37:29 can issue in one place and verify in
37:32 another because they're speaking a
37:33 common [inaudible]
37:34 We hope!
37:35 – Those systems that's
37:38 obviously the…
37:40 But that makes it
37:42 hard, right?
37:42 – In contrast with Aadhaar in India and in
37:45 contrast with what they're doing in
37:46 Estonia because they do not have that
37:48 property and they're not even trying.
37:50 It's a giant centralized system and
37:52 everybody phones home to the mother
37:53 ship.
37:54 – Yeah, absolutely.
37:55 – My point is just having those two
37:57 components up there describes Aadhaar.
38:01 That's my point.
38:04 – Okay.
38:06 – And it does…
38:08 going back to your point about control
38:11 because decentralization is about
38:14 autonomy and control ultimately.
38:23 – (Lawrence) Lessig famously said that “code is law”
38:27 and there's a lot of people who take
38:30 that to heart and it is true to the
38:32 extent that code controls what you can
38:35 do and what you can't do but I don't
38:38 think for identity that idea is quite
38:40 sufficient. That we need more than
38:44 code, we need this underlying legal
38:48 foundation that SEDI provides for
38:50 individuals.
38:57 SEDI answers questions about who has
39:00 authority to revoke, when can they
39:02 revoke? That's just one example.
39:05 Who has the right to get one of these?
39:09 Code doesn't solve those problems. Those
39:11 are all things that we need legal
39:13 infrastructure which is steady, at least
39:17 on the road to providing. I don't
39:20 think this will be the last SEDI
39:21 statute. I think there will be more but
39:23 but nevertheless we're on the
39:25 road to getting there. So
39:29 SEDI provides this legal foundation like
39:31 I've said.
39:33 We've got
39:36 code, we've got stacks that are maturing.
39:40 And what we have now starting in May
39:45 is a legal foundation for all of that.
39:49 So,
39:52 we've had some discussion going back.
39:53 I've got like two or three minutes I
39:55 think if there are questions. Two
39:56 minutes I'm told. So, is there
39:59 questions? Happy to answer them.
40:01 Otherwise, I will turn you over to the
40:03 next one. [Applause]