The SSI Orbit Podcast – Self-Sovereign Identity, Decentralization and Digital Trust cover image

The SSI Orbit Podcast – Self-Sovereign Identity, Decentralization and Digital Trust

Latest episodes

undefined
Feb 10, 2023 • 1h 13min

#48 - Is History Repeating Itself or Are We Operating in a Context We’re Not Aware Of? (with Tim Bouma)

Tim Bouma is the Director of Verification and Assessments at the Digital Governance Council, a Canadian non-profit organization dedicated to developing standards for the Canadian Digital Ecosystem. Tim's current area of focus is developing conformity assessment schemes for standards related to digital trust identity. About Podcast Episode Read more about the episode by heading to https://northernblock.io/is-history-repeating-itself-or-are-we-operating-in-a-context-were-not-aware-of/ Some of the key topics covered during this episode with Tim are: Why is understanding your context and others' contexts important important to prioritize in life? How Tim’s new mental model has helped him better understand context, identity, trust and more (model linked below in resource section). The relationship between roots of trust and the centralization/decentralization of societal administration. How we can look at life through two realms: the physical and imaginary realms. How have these two realms evolved throughout history. The origin of personal names! Understanding how registries of claims and balances work and are managed. How the transfer/unlocking of new knowledge has been a catalyst for power dynamic shifts throughout history. Why architectures are important in shaping culture, beliefs, values, intentions, etc. Should we focus less on identity and more on context? How the separation of cryptography-driven protocols from applications shifts knowledge, which in turn shifts power dynamics. Where to find Tim? LinkedIn: https://www.linkedin.com/in/trbouma/ Twitter: https://twitter.com/trbouma Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Jan 27, 2023 • 56min

#47 - Mobile Driving Licence (mDL): Exploring ISO 18013-5&7 (with Andrew Hughes)

Andrew Hughes CISM CISSP is Director of Identity Standards at Ping Identity. He is a digital identity strategist contributing to international standards development. He works with international associations and standards bodies as a domain expert, developing standards and related conformity assessment materials. Andrew serves on the Board of Directors of Kantara Initiative, and as the Chair of the Kantara Leadership Council. As a national expert delegate for Standards Canada on digital identity, he contributes to development of international standards at ISO SC 27 for identity management and ISO SC 17 for mobile driving licenses and mobile eID. Andrew is currently investigating how the worlds of Government Issued Photo ID can co-exist with the emerging Verifiable Credentials models, in a mobile-first manner. About Podcast Episode Read more about the episode by heading to https://northernblock.io/mobile-driving-licence-mdl-exploring-iso-18013-5-7. Some of the key topics covered during this episode with Andrew are: Distinguishing the mobile driving licence (mDL) credential type from a verifiable credential (VC). How the mDL standard is working towards being consumed by other credential transport protocols (e.g., DIDComm, OIDC4VC) Can the same ISO standard for mDL be used to issue non-driving licence credentials? And should it? Do issuers of driving licences consider mDL it as a driving licence credential, or an identity credential? What does the ecosystem look like for mDL vs the one for physical driving licences? Who are some new participants that aren’t involved in physical DL production and governance? Why implementation supersedes the standard work. What are some interesting use cases around mDL that are gaining traction? How ISO works and how the relevant mDL sub-committees are evolving the standard. Are there concerns with the mobile hardware and OS providers gaining too much control over the mDL credentials? Where to find Andrew? LinkedIn: https://www.linkedin.com/in/andrew-hughes-682058a/ Twitter: https://twitter.com/IDIMAndrew Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Jan 13, 2023 • 46min

#46 - Selling Solutions, Not SSI Technology (with Riley Hughes)

Riley Hughes is the Co-founder and CEO of Trinsic, a company which provides infrastructure for building user-centric identity products. Customers need solutions, not SSI technology. We will struggle in fostering adoption if we try to sell SSI technology to end customers. We should rather focus on selling them solutions to business problems. For example, Slack sells productivity/collaboration tools to enterprises, not Internet technology or communication protocols. The same approach should be taken but us identity folks! About Podcast Episode Read more about the episode by heading to https://northernblock.io/selling-solutions-not-ssi-technology-with-riley-hughes. Some of the key topics covered during this episode with Riley are: Since we recorded the last episode (Episode 10), how have the value propositions and adoption of SSI changed? What are the different ways that SSI adoption is happening, and what ways are easier than others to push adoption? Do Enterprises see any incentive to issue digital credentials? Why the term ‘Digital Wallet’ is a bad analogy for what they actually are, and why it’s not positioned well to be a solution to business problems? Does Digital Identity still have an Identity problem? Why is terminology important to be used under the right contexts? Where to find Riley? LinkedIn: https://www.linkedin.com/in/rileyparkerhughes/ Twitter: https://twitter.com/rileyphughes Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
5 snips
Dec 22, 2022 • 56min

#45 - One Trust Spanning Protocol & Many Trust Tasks (with Drummond Reed)

Drummond Reed has spent a quarter-century in Internet identity, security, privacy, and trust infrastructure. He is Director, Trust Services at Avast after their acquisition of Evernym, where he was Chief Trust Office. He is co-author of the book, Self-Sovereign Identity (Manning Publications, 2021), and co-editor of the W3C Decentralized Identifiers (DID) 1.0 specification. At the Trust over IP Foundation, Drummond is a member of the Steering Committee and co-chair of the Governance Stack Working Group and the Concepts and Terminology Working Group. At the Sovrin Foundation, he served as co-chair of the Sovrin Governance Framework Working Group for five years. About Podcast Episode Read more about the episode by heading to https://northernblock.io/one-trust-spanning-protocol-and-many-trust-tasks-drummond-reed. Some of the key topics covered during this episode with Drummond are: Does the new ToIP Technology Architecture Specification address the questions posed by Kim Cameron in his 2005 whitepaper? If we agree that one identity system cannot rule them all, how then can an identity metasystem solve interoperability across identities, identity systems and contexts? (hint: a trust spanning protocol!) What are the leading contenders for becoming the trust spanning protocol? What are some examples of trust tasks, other than credential exchange, that are possible to unlock? How does a trust spanning protocol x trust tasks lead to advancements in how we manage our relationships, and help us move away from phone numbers and emails as our most valuable identifiers? Where can governments participate within the hourglass model framework to accelerate digital trust on the open internet? Where to find Drummond? LinkedIn: https://www.linkedin.com/in/drummondreed/ Twitter: https://twitter.com/drummondreed Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Dec 16, 2022 • 59min

#44 - Seeding a Digital Trust Ecosystem (with Nancy Norris & Kyle Robinson)

Energy and Mines Digital Trust (EMDT) was established by the Government of British Columbia (B.C.) to incentivize the formation of a digital trust ecosystem that will result in accuracies and efficiencies when sharing sustainability data, with downstream impacts of contributing towards a low-carbon economy. Reporting environmental impact data can be a complicated and laborious process. Data is difficult to exchange internationally, and consumers cannot always access, or trust, reported data. A digital trust ecosystem builds confidence between organizations, businesses, and individuals when interacting online. When information is shared using digital credentials, everyone can trust that the information is current and hasn't been tampered with, even without pre-existing business relationships. For natural resource companies, this means it is possible to easily share trustworthy data to prove their sustainability efforts. In this podcast episode with Nancy Norris and Kyle Robinson, we discuss: What’s happening in climate change legislation globally? What are the sustainability reporting requirements that the mining industry faces today? Where do digital trust and digital identity fit into sustainability reporting? How do you start a digital trust ecosystem? How do you select initial use cases to focus on? What is the role of the government in growing a digital trust ecosystem based on policy? How did EMDT build their digital trust governance frameworks? Why did EMDT publish their governance frameworks to open source repositories? The best ways to educate both technical and non-technical stakeholders about digital credentials and digital trust. Can digital trust technologies alter/influence change in regulatory reporting processes? Can governments who participate in digital trust ecosystems find new ways of creating value/new business models/enhancing standard service offerings? About Guests Nancy Norris, Senior Director of ESG & Digital Trust in the Ministry for Energy, Mines and Low Carbon Innovation for the Government of British Columbia. LinkedIn: https://www.linkedin.com/in/nancy-norris/ Kyle Robinson, Senior Strategic Advisor for the Energy & Mines Digital Trust project on behalf of the Government of British Columbia. LinkedIn: https://www.linkedin.com/in/kylegrobinson/ Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Dec 9, 2022 • 1h

#43 - Governance and Trust (with Scott Perry)

Scott Perry is a Principal at Schellman where he heads up its crypto and digital trust services. Scott is a recognized global leader in digital identity, blockchain, and verifiable credential governance and accreditation. He has worked with the world's most respected SSL-certificate issuers, aerospace and defense companies, and government agencies such as the US Senate Sergeant at Arms and the US Nuclear Regulatory Commission. He is a Steering Committee Member of the Trust Over IP Foundation and Co-chairs its Governance Stack Working Group. He has authored and contributed to most of its governance and assurance publications. As a hands-on crypto and cybersecurity consultant and auditor, Scott provides deep and impactful advice that you would expect from a leader in the field. About Podcast Episode In this podcast episode with Scott, we discuss these topics: In digital trust infrastructure, these “rules” are formally known as a governance framework (GF). A core thesis of ToIP architecture is that interoperability of GFs is just as important—if not more so—than interoperability of the technical protocols. Why? Can you replicate, or codify existing physical world governance frameworks for digital use? Where is governance created? On the edge (with the issuers, holders, verifiers), or within/across ecosystems? Defining trust - is a technical or human concept? How to quantify trust? Is it even possible? Is accountability the key factor in building a rule system to promote trust? Does unlocking certain governance frameworks correlate directly to the adoption of digital trust ecosystems? How is assurance used as a measure to manage risk across various contexts? Are governance frameworks composable, meaning can they be re-used across various use cases? Can we leverage governance frameworks from closed ecosystems and re-use components in open ecosystems? How does governance map to the new ToIP technology architecture model? How do private and public sectors collaborate on defining governance for large scale digital ID programs? Where to find Scott? LinkedIn: https://www.linkedin.com/in/scott-perry-1b7a254/ Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Nov 4, 2022 • 54min

#42 - AnonCreds: Anonymous Credentials (with Stephen Curran)

Stephen Curran of Cloud Compass Computing, Inc. is a Software Development and DevOps veteran who dove full on into the identity on blockchain world in 2017. Working with the British Columbia Government, Stephen has helped define, build and launch the Verifiable Organizations Network (VON)—a production instance of the Linux Foundation’s Hyperledger Indy, Aries and Ursa projects that makes public information about organizations (incorporations/legal entities) in BC available in the form of verifiable credentials. Stephen is a regular contributor in the Hyperledger Indy and Aries community, facilitating discussions and driving interoperability. Stephen has presented on Blockchain and the Hyperledger Indy and Aries projects many times and is a member of the Sovrin Foundation’s Board of Trustees and Technical Governance Board. About Podcast Episode Some of the key topics covered during this episode with Stephen are: Introduction to Various Credential Types - AnonCreds and different types of W3C credentials Converting AnonCreds VC to W3C VC Standard format and adding other signature types (e.g. LD-Signature/NIST/ed25519/BBS+) History of AnonCreds - blinding signature work in the 1970s, advancements and track record since then Why are AnonCreds suited for Government Digital ID use cases? Capabilities provided by AnonCreds - non-correlability, minimizing data shared, zero knowledge proofs (ZKPs), etc. Comparing transferable vs non-transferrable credentials Can the way that W3C credentials are formatted get in the way of interoperability in the future? Are there use cases where AnonCreds aren’t the right implementation? Are AnonCreds more computing intensive than W3C credentials? Future for AnonCreds and for Hyperledger Indy Why Revocation remains the weak point of AnonCreds and Indy Is mDL better suited than AnonCreds for Driver's Licence use cases? Where to find Stephen? LinkedIn: https://www.linkedin.com/in/stephen-w-curran/ Twitter: https://twitter.com/scurranC3I Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Oct 21, 2022 • 52min

#41 - Converging Towards a Common Trust Spanning Protocol (with Drummond Reed)

Drummond Reed has spent a quarter-century in Internet identity, security, privacy, and trust infrastructure. He is Director, Trust Services at Avast after their acquisition of Evernym, where he was Chief Trust Office. He is co-author of the book, Self-Sovereign Identity (Manning Publications, 2021), and co-editor of the W3C Decentralized Identifiers (DID) 1.0 specification. At the Trust over IP Foundation, Drummond is a member of the Steering Committee and co-chair of the Governance Stack Working Group and the Concepts and Terminology Working Group. At the Sovrin Foundation, he served as co-chair of the Sovrin Governance Framework Working Group for five years. About Podcast Episode Digital Trust Infrastructure is quickly becoming essential from an economic, political and security standpoint. Much of the infrastructure today is controlled and owned by device OS providers such as Apple and Google. It’s important that digital trust infrastructure providers can compete with the device OS providers. To produce a level playing field, we must have open standards and open access to the infrastructure. This applies to both to Governments and Private Sector digital trust providers. Some of the key topics covered during this episode with Drummond are: Wallets vs Agents – their differences, their relationship and how agents will use more and more contextual intelligence to help you make decisions according to your preferences. Can non-OS digital trust infrastructure providers compete with the device OS providers? (e.g., Apple owns the OS for mobile/desktops/tablets/smart watches) Comparing DIDComm to NFC – if NFC really facilitates security and trust for close distance, do the combinations of digital wallets, digital agents and protocols (like DIDComm) do the same for trust at distance? Trust Spanning Protocol – establishing authentic connections where both parties can authenticate each other (using the same hourglass model as TCP/IP). What are the architectural requirements for this protocol? And how can various protocols (e.g., DIDComm, KERI) converge into a trust spanning protocol? What does DIDComm do better/different than other data exchange protocols? (such as OAuth2 and OpenID Connect) Can the Trust over IP stack be used outside of Identity use cases? (e.g., payments, data sharing, social media) Comparing SSI to Email – similarities in protocol design, asynchronous or synchronous UX, simplicity and generality Where to find Drummond? LinkedIn: https://www.linkedin.com/in/drummondreed/ Twitter: https://twitter.com/drummondreed Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Sep 30, 2022 • 51min

#40 - Are Trust Registries Vital to the Success of Decentralized Identity? (with Darrell O'Donnell)

Darrell O’Donnell is a technology company founder, executive, investor, and advisor. He’s on a mission to help organizations build and deploy real-world decentralized (#SSI) solutions. He advises numerous startups, senior government leaders, and investors. About Episode Some of the key topics covered during this episode with Darrell are: What are the differences between Verifiable Data Registries and Trust Registries? How can Trust Registries help establish the Authenticity of Data? Does placing too much Governance at the Verifiable Data Registry layer cause scaling issues? Why DNS can become an elegant Root of Trust solution to validate the authenticity of Credential Issuers. Who in the Trust Triangle benefits the most from Trust Registries? Trust Registries vs Machine Readable Governance. About the Trust Registry Specification v1.0 at the TrustOverIP Foundation. How do I trust a Trust Registry? Do Trust Registries create new Centralization points? How will Trust Registries become adopted? Where to find Darrell? LinkedIn: https://www.linkedin.com/in/darrellodonnell/ Twitter: https://twitter.com/darrello Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/
undefined
Sep 8, 2022 • 54min

#39 - Digital Notarization Can Kickstart Digital ID Ecosystems (with Dan Gisolfi)

Dan Gisolfi is currently leading the delivery of innovation capabilities across Discover Financial Services (DFS), such as Hack-aaS, Patent Program, Design Thinking Services, and an Innovation Accelerator. Prior to joining DFS, he led an innovation team focused on the incubation of IBM Security’s Zero Trust Architecture in collaboration with internal labs, academic institutions and NIST. About Podcast Episode Some of the key topics covered during this episode with Dan are: How does the chicken and egg problem relate to digital identity? Is there a dependency on Government IDs to seed the marketplace? Are unique identifier databases required to become a credential issuer? What is transitive trust? And how does it differ from how trust gets established otherwise (e.g., through backend API calls)? The missing role in the trust triangle: The Examiner. Can Examiners become digital notaries? Rethinking authentication and authorization - using attestations from multiple issuers helps to create more trust. How Issuance can become a business model for many trusted service providers. Some challenges with the mDL (ISO/IEC 18013) standard. The benefits of using a Microcredentials approach. Misconceptions about becoming credential issuers (e.g., assuming liability, data minimization). Where to find Dan? LinkedIn: https://www.linkedin.com/in/vinomaster/ Blogs: https://www.ibm.com/blogs/blockchain/author/dan-gisolfi/ Follow Mathieu Glaude Twitter: https://twitter.com/mathieu_glaude   LinkedIn: https://www.linkedin.com/in/mathieuglaude/ Website: https://northernblock.io/

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode