TFTC: A Bitcoin Podcast - #744: Your Face Is Not A Password with Gerald Glickman

Episode Date: May 11, 2026

Marty sits down with Gerald Glickman to discuss the urgent need for Bitcoiners and policymakers to embrace cryptography-based decentralized identity standards that preserve privacy and individual sove...reignty before the window closes on a surveillance-based digital ID future. Gerald on X: https://x.com/GeraldGlickman STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/yHGkvYxdqT Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Bitkey https://bitkey.world/ Aven https://www.aven.com/bitcoin CrowdHealth https://www.joincrowdhealth.com/tftc Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/

Transcript
Discussion (0)
Starting point is 00:00:00 you've had a dynamic where money's become freer than free if you talk about a fed just gone nuts all all the central banks going nuts so it's all acting like safe haven i believe that in a world where central bankers are tripping over themselves to devalue their currency bitcoin wins in the world of fiat currencies bitcoin is the victor i mean And that's part of the bull case for Bitcoin. If you're not paying attention, you probably should be. Gerald Glickman, welcome to the show, sir. Thank you.
Starting point is 00:00:39 Great to be here. I'm freaked for context of how Gerald and I met. We met outside of the TFTC and PubKey bus in Miami. When was that, four years ago? Five years ago now at this point? Yeah. at the time you were working in the banking sector helping uh correct me if i'm wrong if you're comfortable me saying this if not we can cut it out but uh helping cannabis businesses get
Starting point is 00:01:05 uh get banks uh bank accounts and navigating the regulatory landscape that comes with running a in a business that is perceived to be uncouth by by the government and so you're on the ground there correct yeah and went there because they had a they had a crypto banking portfolio that i wanted to support uh the bank was called mvb bank they're still called mvb bank but yeah it was there in a fraud and identity risk management kind of oversight role so you know you're there was a lot of we also did uh gambling you know fan duel and draft kings um so all the all the things that maybe big banks didn't want to touch mvb was was all about it Yeah. And so that's your background. But while we're here to talk today is digital identity. This is something that you've been passionate about. We've talked about for many years behind the scene, and I think we should just jump right into it.
Starting point is 00:02:02 i think when most people hear digital identity their eyes glaze over but you argue that we're at an inflection point in your mind what broke that made this whole conversation about digital identity urgent and what misconceptions do bitcoiners have around it um what broke well um Start there. Yeah, I mean, I think the. The model for digital identity broadly in the United States has been breaking for a few decades, certainly a step change in AI and LLMs generative content has accelerated that to the point where, you know, fraud and identity risk managers, you know, the half life of new controls that they're putting into production. And it's just in a nosedive. But fundamentally, the paradigm is broken in and of itself, like the security model of how we do identity, which is, you know, we're effectively using our identifiers, right? Like our name, address, social security number, these types of things as our authenticators, basically using that information and possession of that presentation of that information. to prove that we are ourselves or, in a lot of cases, somebody else.
Starting point is 00:03:27 And this is a fundamentally flawed model. It's based on the assumption that that information is a secret. Maybe at one point it was a secret. It hasn't been a secret for years, like decades, right? Everybody knows their private information is massively compromised. You would think that that would mean that we have to change the way that we do identity verification. I think you'd be right, but we haven't done it.
Starting point is 00:03:50 So over the years, I've seen more and more, you know, fraud risk managers in the business. You know, these are not bad people. They're trying to protect the corporations that they work for and their clients from fraudsters. But the way that they've been trying to keep that edge and maintain their performance, you know, in these probabilistic systems is to consume more and more aggregated information, including biometrics. And I've been particularly alarmed at that. That's the type of thing that you don't get back. You know, you can't you can't rotate your face. You can't rotate your fingerprint. We should presume that information is going to be compromised, like all other secret information that we trust centralized third parties to protect. And once that information is compromised and already has been, you're not getting out of that hole and you have you have no other trigger to pull.
Starting point is 00:04:44 So, yeah, I think the model has been breaking Bitcoiners and many other people all around the world have significant concerns about the proliferation of digital identity. No one can argue that it's a significant vector for authoritarian control. This isn't a hypothesis. We can just look around the world and see this. Um, and, you know, for me, um, I've historically been, you know, working in financial services and, uh, been on the inside. I've also worked at, you know, led the fraud team at one of the largest identity verification companies during the height of COVID as well. So I have the public sector kind of experience as well.
Starting point is 00:05:28 And, and, uh, you know, we, we want to make sure that, uh, as practitioners in the space, we have a sense of the work that we're doing and how it's connected to the root problem and the systems that we're operating in. And I fear that most people don't. And yeah, as these things accelerate globally, I mean, even the United States, many states are rolling out digital driver's licenses. I feel, you know, as though it's really, really important for everybody to understand how these things work, how they don't work and what other tools, technologies, approaches and policies are out there that we should consider um refine and advocate for yeah i guess going from there it seems that the power structure whether for nefarious reasons or
Starting point is 00:06:19 legitimate reasons has identified that this system is broken it cannot persist in its current form and we need to transition to a new way of verifying individuals particularly in the digital world verifying that individuals are who they claim to be in the digital world and there's a plethora of solutions that have been brought to market e-verify obviously world coin and the orb and the preconditions of a digitalized d system that leverage leverages some form of blockchain technology or some government database that consolidates it. And so I think with that context, what in your mind are the proposed solutions today? What do they maybe get right?
Starting point is 00:07:09 And what do they get terribly wrong? Yeah, so let's start with kind of both ends of the spectrum. One is pure knowledge-based identification and verification. Fundamentally broken, right? We cannot use these systems anymore. everyone's information is massively compromised um i've written and said before that that that security model is is effectively using your address to your home as the key to your front door right like no one would do that uh but that's effectively what we're doing we're using now
Starting point is 00:07:46 public information that was once secret as a means of authenticating ourselves we cannot do it doesn't work um and in many you know not even high assurance but even like medium assurance use cases like practitioners kind of have moved away from that but you still see that for low assurance verification use cases in the public sector it's bad um the other end of the spectrum i would say is full-on biometrics like the world coin piece that you mentioned of like using your uh identifiers uh you know your biometrics uh as authenticators as as well um and um it's you again you can't give that back right like you're handing that over to a private corporation they might make claims about oh we delete it i don't know i mean i don't i
Starting point is 00:08:36 I don't know why anybody should believe that. But it's it's just not a great idea. The things that I advocate for are largely around open standards. These are not my ideas, by the way. These are other people's ideas. They've done the work. I've just kind of discovered them as a practitioner looking for better answers. um and the approach there is to really you know use cryptography to secure um the attestations that we make the same way that we secure the rest of digital life right um with with private keys and public keys um and this fully satisfies what i call like authorship fraud right so basically how do i know that the attestation that marty made actually made it well like i can grab his
Starting point is 00:09:26 his public key i can verify the digital signature and now i'm not relying on probabilistic inference of like taking a picture of a driver's license like i'm using cryptography and math uh to to provably know that um you authored this attestation so um that doesn't mean i should trust it right of course like it's just something that you said and i can prove that you said it or wrote the message and signed it that that doesn't mean that like i should rely on the message so that's like a whole other thing in terms of like trust frameworks and credentials and things like that but broadly my advocacy is around uh open standards um and frameworks that are and policies that are going to empower people to be able to control their identities the biggest thing for me
Starting point is 00:10:14 marty being a practitioner in this space is and and again knowing how it works in the private sector in the public sector is just seeing the results right like in the next hour this conversation at least 3,000 Americans will be victims of identity theft this is unacceptable like we're just doing it wrong right it's like through no fault of their own there's
Starting point is 00:10:35 this there something is happening to them because of our approach that is going to have a massive negative impact on their life it's just unacceptable as somebody in the space so yeah I'm I'm all about open standards cryptography empowering individuals and actually like doing a better job
Starting point is 00:10:51 at preventing fraud Yeah. I mean, and just to add to those numbers, I think you've written about 3 trillion in fraud across federal programs in two decades, 4,000, more than 4,000 breaches per year, deepfakes, fooling automated systems, and it's only accelerating with AI. Yep. Yep. then yeah so that's what i mean so i agree i think this problem needs to be solved and matt and i talk about it particularly on rhr because we do the live stream via the via noster and then matt will go to the official rhr account and post a note of of the video and that post that note comes signed with our um with our private key associated with the
Starting point is 00:11:39 rabbit hole recap account so you know that like hey we have access to the private key nobody else does we're signing and attesting that this is the real rabbit hole recap of this week but getting into it like obviously nasser you can use your real name um but most people use it pseudo anonymously and so that's what i'm trying to get a better understanding of uh when once we transition to a world that is, whether you like it or not, likely going to necessitate the use of digital IDs. What is the spectrum of acceptable types of IDs? I imagine I will keep my Nostra account. I have a web of trust associated with my public address on Nostra. I think I've been using it for five years now. So I think people trust that it is me and know that it is me. And
Starting point is 00:12:33 I've built up a reputation there and that reputation associated with my nostrachy should be able to enable me to interact with people that need a degree of trust on the web. However, is that going to be okay with governments, with tech companies, with other actors that may demand a form of digital ID in the future? Yeah. Yeah. So there's a lot of, there's so much to talk about here.
Starting point is 00:13:03 Um, the first thing I would say is, um, and to give some credit, my views here are significantly influenced by Christopher Allen, who's been in this space for a long time. If you don't know that mission for sure, but, um, trust, when we talk about trust and digital trust, like trust is a contextual thing, right? Like it's, it's not a one or a zero concept. Um, and I think the easiest way to think about trust in a digital context is to kind of step back into the meat space and think about how we develop and manage trust, uh, in the physical world. And, you know, trust is, is contextual, right? Like, um, and, and usually if you want
Starting point is 00:13:47 to engage in, in some kind of relationship, private, commercial, whatever, like it's usually progressive, right? Like you're usually sharing more and more information and establishing like a higher level of assurance and trust, maybe even getting third parties involved to validate the claims that other people are making if it really matters to you um so i think the context is like always the first thing to start with like if it's making a post on social media and knowing that like marty authored it cool like that's a pretty low risk thing it's probably more medium or maybe even higher risk for you but like that's that's you what it's different for me it's going to be different for everybody else um so i think i think that's kind of always the first thing to start
Starting point is 00:14:29 with is there's like we're so trained as modern humans to like look for a singular answer in all contexts and like we just have to like stop that right there like it's that this is like not how this works um so context is king when it when it comes to like the different methods and like what's what's uh acceptable in different contexts both for individuals for businesses for states um it's actually interesting so today um there's some legislation going into effect in utah called steady state endorsed digital identity uh which is really interesting um it's it's also we can talk about this later about like uh you know no single person or entity is like a universal actor like also today utah's like vpn ban it's not quite a ban but it's effectively a ban is also going
Starting point is 00:15:23 into effect so on one hand we have this super great uh digital identity infrastructure and bill that protects individual liberties we'll talk about that more and on the same day we have this like vpn issue going into effect so like it's very confusing if you're just looking at it from a high level but seti um in utah would actually allow you to bring your own identifier like an mpub um and as long as you demonstrate control over that public identifier you know sign a message with your with your insect private key um the state will actually issue a credential to your public identifier and it sounds like okay well it's like so what who cares um but it's actually a really kind of profound like architectural thing in the sense that um it's it's giving
Starting point is 00:16:14 control back to individuals because if let's say for example the state issues your driver's license the subject in it is your decentralized identifier um let's say uh you get into a bunch of accidents you get your license revoked they have to pull it for a lot of people you know the license in the united states is like your primary identity document and having that revoked has a significant impact on your life with this model you would retain control over your identifier now it's just your credential is no longer valid you can't really present it anymore but you haven't been like rug pull in terms of your entire identity so yeah your your credential to drive has been taken from you correct correct but not your the foundation of your of your digital and physical
Starting point is 00:16:58 life when it comes to identifying yourself so you know noster um is certainly interesting there are a lot of different decentralized identity like methods and basically it all comes down to like where do you anchor the the actual public identifier such that people can get the information that they need about you know the cryptographic schemes and other things to be able to verify your digital signature so um you can anchor an identifier in a lot of different places in a lot of different ways and these different ways again going back to context um are more appropriate given different contexts right but um for example like most people are familiar with like domain names you could anchor a did on a domain name pretty easy for institutions
Starting point is 00:17:43 the dependency there is dns um most people don't know how like dns is actually managed but it is like centrally managed and controlled um most people find it acceptable but like there are trade-offs with all these things um you can anchor it in like a social media public key like noster which is like portable to a large degree you're relying on the network of relays um the right off there around are around like uh correlation and like key rotation with that with that specifically um you can anchor an identifier on a blockchain um which can give you you know some sense of like neutrality and durability uh but again you have like the public kind of metadata risks there um and there are some emerging methods that are um more like
Starting point is 00:18:30 self-contained i would say uh with no external dependencies i would point to like harry um and xid from chris rowan and blockchain commons folks where the continuity there really comes from like signed control over like a key registry that you make that you maintain that you can give to somebody you can anchor it somewhere else but it's basically like a log that you can present um and it has the cryptographic assurance throughout that whole thing so um it really depends on the context um and like where the continuity comes from and the assurances come from but um ultimately like the design choices like do matter in terms of like who can sensor and route and like recover and correlate or like take away your ability to represent yourself in
Starting point is 00:19:12 these contexts well i mean it's a perfect point to bring up what are the what are the black mirror scenarios that can unfold if we get this wrong man um it's it's really interesting i think about this a lot um is kind of the the jevons paradox of it all right like um by being an advocate for these tools and advancing the standards and ability for people to be able to do this in a in an easier way uh yes the goals are are ease of use but largely the goals are around like privacy and like individual empowerment but nonetheless like it has to be easier or else people won't use it but given that one of the goals is to make it easier like going back to jevin's paradox like we don't want to enable a
Starting point is 00:20:04 world where um we're now like being asked to present our papers to like you know go into the public square digitally um or physically right um so i think one of one of the guiding principles that i like to kind of true back to is like whatever the rights and norms are in the physical space around identification like we should look to preserve and fight for those in a digital context um so the the black mirror you know manifestation um we again we don't have to look far like these things are happening today you've talked about china social credit scores ability to access like basic public services and have it impact like you know your eligibility for transactions in the private sector as well like we do not want that we do not want over identification just because
Starting point is 00:20:53 identification is now easier um what we're trying to do is make it easier for people to retain their privacy and even claw some of that privacy back uh and do so in a way that they control and is also can be done you know easily um yeah and uh you saw me fidgeting over here because as you were saying that this is something that we covered yesterday in the bitcoin brief i'm not sure if you solved with the guard act protect the children yeah trojan horse for digital identity like basically in the past the senate judiciary uh committee 22 22 to 0 requiring age verification for all chatbot slash ai users by partisan unanimity um to to basically try to throw age verification and i think that's another important topic to bring up is the nefarious ways and
Starting point is 00:21:45 framings that governments will use to trojan horse centralized uh panopticon digital ids on on the masses and i think age verification is the number one way that they'll do that people are not wrong you're like i i the fear is grounded um this is this is often um the vector and framing that is presented to the public around safety protecting the children what we what we have to true back to is again the principles of uh what are the expectations in the physical world and do i have to identify i don't have to identify myself identify myself when i go into walmart as an example but if i go to walmart.com like i am like behind the scenes being identified right and and there's all and and i've agreed to it whether or not i understand what i clicked when
Starting point is 00:22:38 i said i allow cookies or what you know it's it's such a mess um but like yeah we need to find a way to build and amplify the standard policies and tools to like get us closer back to those real world expectations of privacy it also is very troubling you know not just the age verification stuff but like i mentioned utah's um effective like vpn ban uh as well which you know the net effect of that and it's not again it's not really a ban it's more nuanced than that but like the likely result is that like vpns will be less used and you know sites will either block users that are using vpns or you know in an effort to like mitigate this liability that is now on them they will attempt to like age verify everyone right and we'll be you know in this world where
Starting point is 00:23:29 it's like a norm to hand over all of your basic personal identification information just to you know, read the news or check the weather. That's, we have to make sure we avoid that outcome. So freaks, this rip of TFTC was brought to you by our good friends at BitKey. BitKey makes Bitcoin easy to use and hard to lose. It is a hardware wallet that natively embeds into a two or three multi-sig. You have one key on the hardware wallet, one key on your mobile device and block stores a key in the cloud for you. This is an incredible hardware device for your friends and family, or maybe yourself who have Bitcoin on exchanges and have for a long time, but haven't taken a step to self-custody because they're worried about the
Starting point is 00:24:08 complications of setting up a private public key pair, securing that seed phrase, setting up a pin, setting up a passphrase. Again, BitKey makes it easy to use, hard to lose. It's the easiest zero to one step, your first step to self-custody. If you have friends and family on the exchanges who haven't moved it off, tell them to pick up a BitKey. Go to bitkey.world, use the key TFTC20 at checkout for 20% off your order. That's bitkey.world, code TFTC20. What's up, freaks? When you take Bitcoin seriously, you start with custody.
Starting point is 00:24:36 You want to control your keys, avoid single points of failure, and make sure your savings cannot disappear because you or someone else screwed up. That is what Unchained has been focused on since 2016. Unchained is the leader in collaborative multi-sig custody and Bitcoin financial services that keep you in control. They secure over $12 billion in Bitcoin for more than 12,000 clients.
Starting point is 00:24:53 That means about one out of every 200 Bitcoin sits inside an Unchained vault. Their model is simple. You hold two keys, they hold one key, and it always takes two keys to move Bitcoin, meaning their single key can't access your Bitcoin on its own. Just resilient, shared custody that gives you institutional-grade security while keeping you sovereign. Unchained also lets you trade straight from your vault, access Bitcoin-backed commercial loans, open a Bitcoin IRA where you hold your own keys, and set up personal, business, trust, or retirement vaults. They even offer inheritance solutions built for long-term hodlers. or opt for the highest level private client service
Starting point is 00:25:22 with Unchained Signature and get a dedicated account manager, discounted trading fees, exclusive access to events and features, and much, much more. If you want a partner that helps you secure and grow your Bitcoin without giving up control, go to Unchained.com and use the code TFTC10
Starting point is 00:25:35 at checkout to get 10% off your new Bitcoin multisig vault. That's TFTC10 at Unchained.com. Yeah, and I mean, this is something that's been discussed in the world of dids, particularly in the Bitcoin slash Nostra ethos is particularly via zero-knowledge proofs, and please step in if I'm speaking out of line, but there are ways to selectively verify that you are 21
Starting point is 00:26:03 without revealing your exact birthday, right? Absolutely. I think that is where not enough focus is on, And it's a shame that like Web5 blocks initiative fell under because I've talked to Daniel quite a bit and actually talking to him makes me maybe pretty bullish on what they built and how you can do things. I think there's definitely some design choices that they made that others should be paying attention to, maybe go back and see what they were doing. but I think around this selective, um, the ability to verify that you do meet certain credentials that are necessary to interact in the digital world without actually giving up all the information itself.
Starting point is 00:26:50 Yes, 100% point center is also like a big advocate, um, for these types of approaches as well. Um, so grateful for, for, for Daniel Buckner, Peter Quinn center, everybody there, um, who keyed in on these things and has been doing the work um for years and years but yeah you know the outside of a did right so if we think about a did what is it it's it's basically a way it's a decentralized identifier it's a private public key pair cool what does that give us that give us gives us the ability to um verify if somebody authored something great the other piece of this is around credentials right so we talked about the state issuing you a driver's license
Starting point is 00:27:31 with the subject of that credential being your did and not like your dii that's that's fantastic it's it's also not enough right like we don't want to be in a world where it's like cool i have this verifiable credential that i can present um and authenticate with with uh my did by you know using my private key to sign the presentation of the of the credential we don't want to end up in a world where like we're basically just now like taking a copy of the digital credential and now storing that for seven years instead of a picture of your
Starting point is 00:28:03 license which you know it's basically well financial services so the the ideal flow is you know and and the tools and technologies are here like they they exist um they're still emergent around some of the edges but like we do have the ability uh to issue credentials such that they have these these specific proof points in them such that like when I go to the bar I don't have to reveal my birthday I just have to selectively disclose the attestation that's a part of my signed credential from the state that says I'm over 21 maybe maybe that credential also has a picture of my face or maybe that credential requires me to locally like biometrically authenticate myself to the device that the credential is bound to but there's a lot of
Starting point is 00:28:52 different ways that we can we can we can build assurance between the credential and the presenter of the credential um to to ensure that like you know the credential isn't like lost stolen and misused and there's a lot of things that the issuers of these credentials can do to ensure that like the holders of these credentials can present attestations or verified attributes of credential uh without completely revealing like their whole dossier right so um yeah i think that is that is the way forward um there's i can like describe like that ideal flow if you're interested but um that that's like really what we're aiming for is um composability right and the ability to just like share proofs not documents yeah uh please explain the flow because i think it's
Starting point is 00:29:42 important yeah yeah yeah sure so i i think like when i think about the the ideal flow here like i think an issuer um and you think about an issuer who's an issuer i could be an issuer i could say uh i'm going to issue you a credential marty that says you have a red hat i have reason to believe you have a red hat uh can be anything anyone can be an issuer of of a credential or an attestation what i'm going to do then is i'm going to craft that credential in like a standard that allows for privacy preserving presentation of that credential, which is going to allow for selective disclosure and zero knowledge proofs. And it's going to be, I'm going to sign it and it's going to be bound to your public key, right? So you can only present it if you authenticate
Starting point is 00:30:30 yourself with your private key, right? So that completely removes the, what happens if somebody gets ahold of your digital credential, it's useless unless that threat actor also then has private key which if that's the case you have bigger problems um but i'm gonna craft the credential in such a way that i'm gonna say uh marty has a hat marty also has a hat a hat that's red and he also has a rat a hat that uh has a reference to uh the bitcoin park classic golf tournament from 2023 different levels of specificity then you could selectively reveal them as you as you choose um let's say you're going to a bar and uh they're going to say hey like only people that possess red hats um from 2023 can get in here um that's a very specific
Starting point is 00:31:18 request right and and honestly like when you think about going to a bar like they're looking for a very specific request as well like they want to know that you're over 21 they don't care where you live they don't care what your name is if you're an organ donor all that stuff you have to reveal all that to satisfy the requirements. But like, let's say you're at this place, the bar is you must have verified proof that you could, you know, own a Red Hat. I'm going to make that request to you in a format that like your wallet and your credential can directly respond to, right? So I'm going to say, please provide proof of Red Hat ownership. You'll go into your wallet and you'll be like, cool, here's my verified claim from Gerald. I'm going
Starting point is 00:31:59 to i'm going to present this attribute um and there we go now should the bar to the bar trust that that gerald is a is a trustworthy source of authoring this information that's up to them you're a redhead oracle man you're the trusted redhead oracle yeah but again this goes back to like context right like most people at a bar right like you need that attestation needs to come from a state but like in this context whatever it's private attestation you happen to have a credential you can selectively reveal the component of that. So you're going to generate the presentation of that claim with a zero knowledge proof. You present that.
Starting point is 00:32:41 You don't have to hand over your phone or anything. You can do it via QR or maybe even NFC. And it's like a one-to-one non-spaced request, right? Like it's not a replayable thing. They can't take your authenticated presentation of this credential and use it anywhere else. It's a it's a peer wise presentation. The verifier then validates it. Right. So they they take a look at, OK, like who signed this, Gerald. OK, Gerald, like the man, when it comes to, you know, expecting red hats, we trust him.
Starting point is 00:33:15 They might have like a challenge of some kind. And they might if the credential doesn't include it, like they want to make sure that the presentation of this credential is, in fact, like signed by the by the person or the controller of the did. So you could just authenticate yourself to your phone to sign it. You didn't already do that. And what we've done is we've we've enabled like the this club to, you know, protect your privacy, satisfy the information that they want, and they don't have to call me. right like they're as a part of digesting that that um that credential they're not like phoning home to some state agency or gerald's like red hat oracle business to be like hey marty's here at this time at this location does he have a red hat no like the credential stands alone by itself it's anchored to your did and it's built in such a way such that you can select and present
Starting point is 00:34:11 authenticated piece of it so um that's it right you know on and and after that once they once they do all that stuff like they don't need to record your name they don't need to record when you were there they just need to know like hey like this requirement was satisfied and like this guy's in um maybe there's a time stamp maybe they provide some sort of like proof verification result if necessary. But like no PII is exchanged, just the proof and like the requirement is satisfied and people move on. So this can be done in a privacy preserving way using proofs instead of just like handing over a digital credential itself. And that is the way that we should do this for sure. You mentioned that if somebody loses or somebody loses access, maybe not loses
Starting point is 00:35:02 access but somebody else gains access to the private key credentials that you have big problems but i don't want to gloss over that because i think that that is a massive point of friction that is unclear how you solve to me it's like obviously we see this a lot in bitcoin um private key losing private keys or somebody stealing private keys is not uncommon um i want to call it rare i want to call it um i want to call it uh most people aren't susceptible to it or haven't befallen that i would imagine however it does happen and i think this is something that um we're still trying to uh gain a level of comfortability over is developing these new skills of handling private public heat pairs and securing them most importantly so what's your
Starting point is 00:35:57 what are your thoughts on that and how that evolves yeah i mean as we incorporate these kind of approaches um into more and more of our daily life like we need to get better here right like um not not just around like um you know individual responsibility like obviously that's like a key part of it but um we we need to like build systems and capabilities and make conscious choices around like hey if you lose your mpub like that's it right like that's all the protocol supports at the moment there are other did methods and approaches here which do solve for this or attempt to solve for this thing specifically they have other trade-offs um but i'll point to like carry as an example so um they they do like what they call like pre-rotation right so basically you
Starting point is 00:36:49 you have a private key um you can like pre-rotate your keys and like hold multiple private keys such that if you ever lose uh you know an earlier private key um you can broadcast a message that says like please disregard you know any messages from that in the future or if it was compromised etc so i i think that that is like um something that we need to get better here across all of these methods whether it's um like you know collaborative custody kind of setups that you and your audience are probably familiar with around like multi-seg and just the whole the whole spectrum there um or uh building it into the protocol itself uh like carry where you're you can you can pre-rotate now obviously like if you lose all your pre-rotated private keys as well
Starting point is 00:37:36 like what what do you do here um this is this is the problem with decentralized systems there's no hotline to call um but that doesn't mean that we can't build in you know um capabilities and recovery mechanisms in the protocols directly that enable people to like take these precautions so um you'll probably hear that in a lot of my answers it's never like a one or a zero on these things like we should understand the middle ground and like make a deliberate choice that suits our context yeah no it makes sense and i'm thinking of something like with the bit key here like their social recovery maybe there is something you can do with family maybe it would be mandated by the state has to be family members or somebody that's a bedded
Starting point is 00:38:17 close friend and you get two of them and if they're willing to sign on their behalf then you worry about like all right what if they loot against you now i'm rambling but no i it's it's a lot of the same like like systems thinking and like threat vectors um in this context as it is with like bitcoin security as well and private key and self custody so um i think big corners are like uniquely suited to be able to like advance this conversation because like we've already spent years thinking through like all the all these threats manifest uh and like at what level certainly uh you want certain assurances about recovery um again for certain contexts like maybe it doesn't matter at all for others it's like you would never ever consider doing this yourself if
Starting point is 00:39:03 you didn't have um these collaborative recovery mechanisms so yeah again context dependent but um there there are tools and methods today that um that that care for these things it's just um a lot of them are are nascent and uh fundamentally like constrained um given the nature of like hey man it's it's entropy if you lose it like and you're and you did it yourself like that's it yeah all right freaks you know me you know i don't take sponsor money from products i wouldn't use myself so listen up the aven bitcoin visa card is one of the most interesting things i've seen in the bitcoin lending space in a long time here's the deal you can get a line of credit up to a million dollars backed by your Bitcoin without selling a single set. No gains,
Starting point is 00:39:49 no annual fees, no minimum draws, and your Bitcoin is custodied by BitGo, which is one of the most trusted names in digital asset security. AVEN never lends it out. There's no rehypothecation. You stay in control. And guess what? You can lock in a fixed rate for up to 10 years. That's 10 times longer than most lenders out there, or go interest only for up to five years. Rates start at 7.99% APR for a product that lets you keep your stack and still access liquidity. It's hard to beat. I mean, the duration and the rates is the best I've seen in the market to date. You also get 2% unlimited cash back every time you use the card, spend fiat, keep your Bitcoin, the whole game. If you've been stacking for years and you need liquidity without triggering the taxable
Starting point is 00:40:32 event, this is worth a serious look. Go to aven.com slash Bitcoin. That's A-V-E-N.com slash Bitcoin. Check it out. What's up, freaks? This rip is brought to you by good friends at CrowdHealth. I've been a happy CrowdHealth member for almost five years now. My wife and I have had two children while we've been on CrowdHealth, and I actually just got the last bill for our third child funded. It was $6,157. CrowdHealth negotiated down to $2,309, and we only paid $500. The rest was crowdfunded by the CrowdHealth network. If you're sick of health insurance premiums and having to pay deductibles and getting ripped off at the hospital join crowd health it's an alternative way to pay for your health care it's not health insurance it's
Starting point is 00:41:13 crowdfunded health care as you can tell they negotiate prices for you you pay in cash it's much cheaper overall we're much happier they have incredible perks go to joincrowdhealth.com slash tftc to sign up five years on crowd health not looking back joincrowdhealth.com slash tftc use the promo code tftc once you set up your account you're going to get 99 a month for your subscription for the first three months so next up you you've written that the choice is made in the next year or two we'll lock in the architecture for a generation why do you believe this why do you think this window is so narrow right now i mean i'm just looking around man like i i i see the age verification stuff um i see more and more um surveillance in public spaces
Starting point is 00:41:58 um and in in private contexts as well um and i think um you know you you mentioned the angle of safety i think ai like fraud risk managers and identity practitioners have known this for a while that like you know this is a never-ending battle you know with these digital tools but um i think it's become more obvious to folks like the level uh of impersonation risk and i think that amplifies the likelihood that as a society, we will make hasty decisions, um, and buy into simple framings and solutions, right. Of like, Hey, this is a big problem. Uh, it's wasting a lot of taxpayer money, by the way, it's already wasting a lot of taxpayer money, but like, it's probably going to get worse. Uh, so therefore this is what we need to do. And, um, you know,
Starting point is 00:42:51 I've already seen that for years, right? Like the, just the pressure that fraud and identity risk managers have to maintain their level of performance to determine if somebody is who they say they are. And there's a lot of pressure to just like do something, right? And the something that we've been doing is on a path where, you know, we're collecting more and more biometric information, aggregating more and more signals. We have more and more listening devices around us all the time that are capturing and synthesizing and selling our personal information. We should just be very thoughtful about like where that's going to lead us and i think the advances in technology over the last few years have like dramatically accelerated those timelines so
Starting point is 00:43:29 um yeah at a time where we're you know half of the states in the united states have some kind of like age verification dates are rolling out digital credentials uh some of them are done well uh some of them phone home and nobody wants that right but like this is happening right um so there are states in the united states where every time you present your digital driver's license it's a it's a it's a ping back um you know to the issuing authority you know nobody wants that like but this is this is what we're going to have if we don't lean in and put our hands up and say excuse me that is that is not my right and expectation uh as an american in the central context and i i reject it so imagine the amount of blackmail that they could do like
Starting point is 00:44:15 oh hey marty i know you've been telling your wife that you were going to the library to do some research but we see that you were actually just going to the bar down the corner it'd be real shame if she found out we're going to need you to do something about that right but this thing that we want you to do yeah so we we don't we don't want that um and uh we don't expect that right like we there's been massive you know creep i would say in terms of surveillance over the last like five years for sure but really the last like 20 years um you know predominantly through like the way that we monetize the internet honestly like i i started my career in like digital marketing and advertising and have like early you know experience with like these private
Starting point is 00:44:59 identity graphs and like custom advertising and stuff like that um people have had many moments like we as a society have had many moments of like new levels of ick right of like oh i was talking about something with a friend and then i saw this ad like what the hell is that and like it deeply disturbs people for like half a minute and then they're like oh but like that is kind of convenient you know what i mean so um you know this is this is the challenge here is basically trying to get people to deeply understand um that these are these are real fears um this is happening today in other countries throughout the world uh people have much less freedom uh because of these these systems and you know i i want to make sure that if we as americans uh end up in
Starting point is 00:45:51 that spot it's because we understood the risks and we made the choices now like fewer and fewer people are actually like aware and engaged but like that is never going to stop me and i hope it doesn't stop people that are listening to this to like try to make the world a better place and like uphold american values um so yeah man it's i feel like the window is as open as it's ever been for like real change but um it's closing fast well i mean to your point there i completely The masses are never going to take the time to dive into the architecture, digital distributed digital ID systems, decentralized digital ID systems, nor care to weigh the tradeoff. So that begs the question, who are the necessary stakeholders to get this message in these designs in front of? And obviously, I think politicians, the obvious one, maybe big tech is another one.
Starting point is 00:46:52 But I think maybe around, correct me if I'm wrong, is the industry which you come from, which is broad prevention and compliance. And that begs the question, what is the state of their understanding around this topic from your perspective? The incentives are not good, man. You know, when you think about. OK, we want to do a few things. We want to actually like do a better job with determining if people are who they say they are. Cryptography helps with that massively. Fantastic. We want to enable people to be able to present or like hold and present their own like identity related claims.
Starting point is 00:47:35 Fantastic. The rub there is the entire identity verification model. like the industry is like built on a model where like that fully conflicts and like subverts their business model right like these people are getting paid for every verification that happens so if you if you're working inside of one of these companies and you're gonna work at one of these companies and you come forward and say you know what i think we should do we should we should find a way for people to be able to present these claims themselves uh such that they don't have to like take a picture of their face and upload a picture of their uh uh license you know for every website that they go to um you know you're you're gonna hit a wall pretty quickly just given the economics
Starting point is 00:48:19 of the business model so yeah the the incentives are are not good there um same with big tech like they're going to move if they need to um but broadly like this is a source of revenue um and like you know network effects and control for them so they're not going to just like hand it over um so that's why i was excited about SETI um because i i think states will likely need to lead lead the way here um at a federal level we we have seen recent requests for comment from treasury on like um how can you know financial institutions rely on attestations from other financial institutions in the verifiable verifiable credential format right so if uh you've already gone through identity proofing somewhere else uh you know they hand you that credential you can
Starting point is 00:49:10 then use that credential to skip some account opening and like kyc process you then another bank that would be a good thing it all comes back to at this point the trust model like how do i know as bank b what bank a did what their processes were all that stuff and this again goes back to the incentives of like, um, of the context, right? So, um, identity verification today is, is a probabilistic process. The things that influence like the optimization targets of that probabilistic process in a, in a private sector context are profit and loss, right? So if, if you're trying to open up a savings account, um, that, you know, has a seven day funds availability policy and I have very little risk,
Starting point is 00:49:56 like i'm gonna have different thresholds on the identity verification than if you're trying to open up a mortgage and you want me to write you a check for half a million dollars right so just just that realization makes you realize that like the the assurance provided by any financial institution is a function of their own context which makes it hard for other financial institutions to rely on those attestations because who knows what the context was so i think there's some standardization work that needs to happen uh there as well and you know we can nest and uh other other agencies can kind of help with that but ultimately like it you know private industry needs to lead here there's been some good progress and states need to lead um because the the federal
Starting point is 00:50:39 government you know is like they're aware of the problem they haven't really been doing a lot frankly over the last five years yeah well you mentioned there's some good actors in the private sector making some progress in this uh direction you mentioned carry earlier i'm not sure if you believe they're one of them but anybody else in your mind is world coin actually good have i been wrong about world coin or no no you've not been wrong i mean it's just you know there's a reason why it gives people the ick right like you again like this is a very real problem like proving that humans are human um and proving that you are who you say you are like this is a very real problem And I don't know who started that project, you know, same old man, like, I don't know the people.
Starting point is 00:51:27 I do know some people from, like, the standard space that, like, worked there for a little bit and then, like, left shortly thereafter. But, no, like, we should not be using our, like, biometrics as identifiers. Like, it's a great way to authenticate yourself locally, right? like on your device fantastic right doesn't leave your device excellent but we do not want to live in a world where like you're just walking around and like private industry and government can just identify you from just like your face like yeah yeah well i think it's important that you're referencing um face id on the iphone there and i think there's a lot of misconceptions about what's happening there mainly people think that apple is storing your base id on some server that they host
Starting point is 00:52:17 but however like what's happening there is like it's a secure enclave thing so it's biometric verification via the secure enclave that lives locally on your device which is the right model similar to what happens with bitcoin wallets um like i have the the fingerprint biometric here but it's stored in this your enclave yeah yeah and and you mentioned steady as well like i'm not a technical expert there's some um things that i don't fully understand around like steady witnesses and um basically how you build that trust graph there um because there is no like uh external dependency or like anchor so it's like self-contained but they have these like witness network um so yeah i don't fully understand it but i am a fan of like people giving it a college
Starting point is 00:53:05 try and like trying to trying to figure this stuff out but um yeah broadly like we we want to be using um identifiers that are not our biometrics and are not our personal information and we want to authenticate our ability to use those things locally um or with places that we trust a lot like maybe that's you know the dmv like i'll go to the dmv to authenticate myself i'll let them take my picture whatever because i know that they're going to give me a credential that is like of high value for me that i can use in other contexts um that other people are going to trust and use in the biome. So, yeah, I think that's like my general frame is that like using your biometrics as an identifier is not good. Again, see China, like Americans probably, I think,
Starting point is 00:53:54 do not want to live in that world. It results in a world and society where people are just fundamentally less great. I don't want to live there. I don't want that to happen. Yeah. I mean, with the Irish scans, I mean, Minority Report might be my favorite sci-fi movie of all time. And it's just, I just go immediately there. Like the combination of Irish scans and self-driving cars, it's just like Tom Hanks, or not Tom Hanks, Tom Cruise had to go get a new eyeball transplant to avoid the ire of the authorities. um they basically had autonomous drones that were able to go around and scan people's eyeballs to confirm who they were and we're not too far off from that reality right now yeah yeah and it's it and now's the time right like now now that would be like my call to action like now now is
Starting point is 00:54:49 the time for people to um move past the like yeah this is really scary and sucks and like we should avoid this to like, no, like, like these policies and technologies are like being developed out in the open now, like right now. Um, so now, now is the time to move past the black pill into the white pill of like, you know, let's find a way to instill American values around privacy and self-sovereignty, uh, into these tools and policies, um, such that like we don't end up there because I think it's fair you know to just observe that like directionally like we are going that way um and I want people to like be aware of that um and you know it's like yeah is minority report predictive programming where they're just saying hey get ready for this future there's
Starting point is 00:55:43 nothing you can do about it yeah I believe not because the potential like you're describing why we're having this conversation right now is because the potential to avoid that is very real the technology is at our fingertips and if we apply it the right way we can get to the future that's privacy preserving and sovereignty preserving that we would all like to live in and on that note like yes let's move towards this but for anybody listening myself included like what of the low-hanging fruit first steps towards that direction is it interacting with policymakers is it interacting with private industry is it just making noise on exit or is there some technical implementation that people should begin uh interacting with to to signal like hey this is
Starting point is 00:56:31 the direction i would like to go yeah so there's thank you for asking there there's there's quite a few states that are issuing mobile driver's licenses now um for those that are like tech savvy and have the ability like find out how that works like you know are are is your is your state providing you a credential that phones home are you locked into a specific vendor um are you able to selectively disclose attributes of of your um of your digital id um or is this like worse than physical id um the other things i would i would that come to mind are like supporting open standards work right so that i'm a big fan of the w3c um mona sporney has been doing an incredible job there for years and years in the decentralized identity space sam with christopher allen uh as
Starting point is 00:57:21 well co-author of of the original did spec trust over ip open id foundation decentralized identity foundation all these are open to the public they have like a open source like development model anybody can can get up to speed observe contribute um i would also direct people to the seti like model legislation out of utah um take a look at it like there's some great stuff in there um that you know does put some very real constraints not just on the state but on the private sector as well um and puts like a um you know like a digital identity bill of rights if you will in place um to to constrain private sector from just like willy-nilly selling your information um and yeah just like broadly like talk about these things and and not in a
Starting point is 00:58:09 again like understanding the fears and the problems is very important like we need the motivation uh there to like understand like why we care about these things but then try to quickly move into like what we can do um and that's kind of where my journey started as well um with bpi of just like hey like we these conversations are happening i remember i think you were at the the bpi event last year around summertime um and i think on stage warren davidson mentioned digital identity uh akin to the eye of star on yeah yeah and i was like well you know i get it but this is an important point because i think there's a lot of people and i i would have included myself in that camp probably like a year or two ago just like digital identity avoided at all costs becoming
Starting point is 00:58:59 abundantly clear with the emergence of ai that we're going to get ddos'd by computers and robots and there is going to whether you like it or not recognize it or not like we are entering a reality we are living in a reality where we are coexisting in the digital world with robots and humans need to be able to identify each other in that system um yeah and and and the ways that we should do that are the same ways that we create high assurance around any other exchange of information which is we use cryptography right like there's no reason why we shouldn't be doing that for like the layer zero of humanity right like authenticating people so yeah it's not really like a technology pitch it's more like a values pitch like understand what's happening understand
Starting point is 00:59:46 the tools um the white pill is definitely not like everything will be fine it's like it's the tools exist the window is open and like the outcome depends on whether or not like the people who care show up and support places like, you know, Jay Stanley at the ACLU is a great advocate and like fair advocate for these things. Peter at Coin Center. Obviously, you know, your local legislators are like always great people to talk to. But like this stuff is happening regardless of whether or not we want it to. Like the worst case scenario is we don't engage and we continue on this trajectory. So that's why it's like such an urgent moment for us to be able to like, put our hands up and say, wait, let me
Starting point is 01:00:33 learn about this, we figure out what we're trying to do here. And ultimately, like apply the physical world test, right? Like we want to replicate, like, the rights and norms that we have in the physical space to the digital space. We don't want a digital identity, we want to like digitize identity. And that starts with individual control. Not like corporate control and walled gardens yeah and that's what i worry i mean we're seeing with ai already with the hyperscalers trying to position themselves in the technology that they're forging forward as
Starting point is 01:01:11 a matter of national security that that needs to be controlled in a way that you create the regulatory mode the license regime and you can see uh in parallel and you can actually see the same actors obviously with open ai and world coin being loosely connected via the sam alton connection the digital id saying this is critical to national security and digital security and we need the solution now no by the way we have one um you should use this and it's they have a lot of lobbying power they have a lot of social cachet because people are very impressed with what they've built but as we've come to know particularly bitcoiners uh big tech does not always have your your best interest in mind so it is imperative that we we fight for these free open distributed
Starting point is 01:02:01 solutions like the closed garden solutions that that will inevitably be put forth by these actors yeah that's the you know that's that's the defense here open open systems open standards and software um open tools that everybody can use um that that level the playing field here and um you know improve the floor for like our sovereignty as as individuals certainly like private business is not going to go away here the public sector also has like some um you know some some challenges because they have like an access mandate right like we talked about like the the relativity of insurance in a private sector context being a function of like profit in the public sector it's like you know they they have a man of an access mandate right so they have to like over anchor
Starting point is 01:02:53 on like yeah it's probably them um so you get error on both sides um and you know that this is where like this the states and uh private sector can can play a role to um put these different models forward um and ultimately you know hopefully americans who care about liberty and privacy uh will step up and make their voice heard here yeah well that's like the last last topic because again going back to warren davidson's comments and again hand up when like agenda 2030 digital id you'll own nothing and be happy i was a big like avoid digital id at all costs and i think uh it's gonna force an uphill narrative battle because i think many people have viewed a digital id as the mark of the beast a form of the mark of the beast if you will and so
Starting point is 01:03:45 again reiterating what i said earlier but maybe reframing like how do we how do we uh convince people like hey not all digital ids are bad they're probably necessary in this world that we're emerging into unless you want to go live in the woods which if you want to more than happy for you to go do that for yourself but we do have a society and a reality that is going to exist outside of your cabin in the woods and and go down one path or the other there's there's going to be a big narrative and anti-propaganda campaign that needs to be waged as well i've heard you say it many times recently like you may not care about the state but the state cares about you like same context rather um the the alternative to engagement is not like freedom
Starting point is 01:04:34 from digital identity uh the alternative is digital identity like designed without our input right um so we are kind of seeing where that's going um the fight is really over like whether digital identity preserves physical world privacy norms or continues to like erode or fully destroy then um and our goal is to like embed privacy autonomy portability like legal due process and individual control like into the technology and policy stack such that the ability for this like this reality to manifest is severely constrained uh at a fundamental level um it's going to take a lot of work on a lot of different angles but um it's critically important and uh I'm hopeful that many people continue to join the fight
Starting point is 01:05:24 because it really matters. All right, freaks, join the fight. Gerald, thank you for fighting on our behalf as many of us operate blissfully unaware of the progress that's being made. I mean, I'm more aware than most, but I think most people are blissfully unaware of what's happening.
Starting point is 01:05:44 And again, it is uncomfortable because it is um it is a fact that many people including representatives like warren davidson saying avoid the digital id obviously like katherine austin fitz and many others in that part of the world saying avoid at all costs and again i'm sure there will be people that listen to this podcast and say marty marty got turned he's a spook now the cia got to him he's pushing digital id yeah but that's like the weird thing is like again the ability to use cryptography to selectively reveal attestations of things being legitimate without actually revealing the information itself exist and in the world of digital id that is much preferable to the world
Starting point is 01:06:34 coin or the phone home to the government to verify and them knowing everywhere you're going yeah we can we can not just like slow the rate of change here like we can actually revert it with these tools and technologies so like that is what's on the table um how much of that we take advantage of like will be determined in the next few years um and it's i think a lot of people it's very scary and it's so scary that they disengage like i said like that doesn't mean that like these efforts are going to stop so like we need the engagement if it scares you lean in learn more become an advocate um and join the fight gerald it's been an honor and a pleasure where can more people figure or find out excuse me um where you're talking about this where can they follow
Starting point is 01:07:23 you or can they keep up with the progression of the conversation uh as it as it lays as it gets um as it progresses yeah so i'm i'm on uh x i'm at gerald glickman.com but uh you can find me always open to talk to people to help them kind of learn more about this and direct them to things that are of interest to them um but yeah those are those are the two spots all right well i'm sure we'll we'll have more conversations about this over the next couple years as things progress so until next time thank you for coming sir appreciate you marty thank you peace and love freaks thank you for listening to this episode of tftc if you've made it this far i imagine you got some value out of the episode if so please share it far and wide with your friends and family we're
Starting point is 01:08:12 looking to get the word out there also wherever you're listening whether that's youtube apple spotify make sure you like and subscribe to the show and if you can leave a rating on the podcasting platforms that goes a long way last but not least if you want to get these episodes a day early and ad free make sure you download the fountain podcasting app and go to fountain.fm to find that five dollars a month get you every episode a day early ad free helps the show gives you incredible value so please consider subscribing via fountain as well thank you for your time and until next time Thank you.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.