







10 Years of SPIFFE! Express your interest in Community Day 2026 →
Identity is the Platform
This is the talk I gave at Mindtrek in Tampere, Finland. Slides are available here: http://factoryjoe.com/blog/2009/10/01/identity-is-the-platform/
The Path to Self-Sovereign Identity
Today I head out to a month-long series of events associated with identity: I’m starting with the 22st (!) Internet Identity Workshop next week; then I’...

Building the world's trusted identity platform • Yoti
Our comprehensive suite of customer verification tools make it easy for businesses to be compliant and safe for people to prove who they are.

Human identity: the number one challenge in computer science
If the modern ‘problem of identity’ was how to construct an identity and keep it solid and stable, the postmodern ‘problem of identity’ is primarily how to avoid fixation and keep the options open. (Bauman 2011)

IIW – Internet Identity Workshop
The Internet Identity Workshop — where the identity community meets to discuss and advance digital identity.

A Decent Identity Part 1: Theory
This essay outlines a set of capabilities and goals comprising decent social computing and then establishes a framework for assessing how well an ecosystem’s identity system supports those goals and capabilities.
NIST SP 800-63 Digital Identity Guidelines
NIST Special Publication 800-63 Digital Identity Guidelines
'A new industry with a new identity:' Canadian devs in 2026
We spoke to developers at Toronto Canada's XP Game Summit to see how they are getting by in increasingly tumultuous times.

The Heart of Spritely: Distributed Objects and Capability Security
This paper is the second in a three-part series outlining Spritely's thinking and design. The first paper, Spritely: New Foundations for Networked Communities, explains the problems which face contemporary social network design. This paper details the core technical toolbox provided by Spritely Goblins and how it supplies the necessary features to feasibly build out Spritely's broader vision. The third paper in the series, Spritely for Secure Applications and Communities, ties the first two papers together by showing how the architecture for user-facing software fulfills the vision of the first paper and can be built on top of ideas from this paper.
Identity verification on Claude | Claude Help Center
Being responsible with powerful technology starts with knowing who is using it. Identity verification helps us prevent abuse, enforce our usage policies, and comply with legal obligations.

Reclaiming my digital identity — Open Indie
This post is the preamble of a 5-part series called The Great Untangling. The following four posts have already been published and are li...

Four "Digital Identity" lessons every Web3 builder should know - blog.boscolo.co
This article was originally published on Mirror.xyz May 17, 2022
SyRA: Sybil-Resilient Anonymous Signatures with Applications to Decentralized Identity
We study Sybil-Resilient Anonymous (SyRA) signatures, a cryptographic primitive that enables credentialed users to generate, on demand, unlinkable pseudonyms tied to any given context, and issue signatures on behalf of these pseudonyms. Concretely, SyRA allows a distributed issuer to turn any legacy identity or personhood identifier, possibly of low entropy, into a unique associated cryptographic key of high pseudoentropy, for use in generating signatures for any given context. Sybil-resilient anonymous signatures achieve three main objectives: 1) Sybil resilience: every user is entitled to at most one digital identity, 2) anonymity: no information about the user’s real identity is leaked, and 3) non-interactive context switching: users can create on their own at most one credential for any given context in a manner that is unlinkable across contexts. We conceptualize the SyRA primitive as an ideal functionality in the Universal Composition (UC) setting and put forth SASSI, an efficient, pairing-based construction that realizes it by utilizing two levels of verifiable random functions (VRFs), a design which may be of independent interest. The first level consists of threshold VRF issuance of a user’s unique secret key tied to their real-world identifier. The second level allows a user to create signatures for each context, under a unique pseudonym per context. Compared to prior cryptographic tools capable of realizing SyRA, SASSI has the unique feature that issuers are stateless and hence do not need to retain any information about past user interactions, a relevant property for a decentralized implementation. We overview various applications of SASSI in multiparty systems, such as cryptocurrency account management and airdrops, e-voting (e.g., for decentralized governance), and privacy-preserving regulatory compliance (e.g., AML/CFT checks). In the context of creating addresses for digital assets, SyRA signatures enable users to embed their legacy identity into their address in a manner that protects their privacy for each application with which they interact. We demonstrate the practicality of SASSI by providing an implementation and performance evaluation of our construction.

Exposed Persona Frontend Reveals Extensive Biometric Surveillance Stack Behind Age Verification - ID Tech
Security researchers investigating Discord’s age-verification implementation have discovered a publicly exposed frontend belonging to Persona Identities, Inc., revealing that the identity-verification vendor’s platform performs far more extensive checks than users […]

The Digital Identity Event Horizon
A five year investigation into digital identity and its central role in creating brittle societies.