Video summary
The Decentralized Trust Graph Working Group meetup in Geneva marked a significant milestone as the project celebrated its one-year anniversary, bringing together in-person attendees and remote participants to discuss the evolution of digital trust infrastructure. The session introduced the Verifiable Trust Infrastructure (VTI) stack, which moves beyond basic self-sovereign identity tools like keys and verifiable credentials to incorporate "Verifiable Trust Agents" capable of AI-driven communication via the Trust Spanning Protocol. This architecture creates scalable networks where digital twins represent entities with portable, reciprocal relationships, addressing the limitations of current centralized government ID systems that have often failed to gain public trust, particularly in markets like New Zealand where there is a strong resistance to surveillance and a demand for sovereign data solutions.
A core innovation presented was the transition from SSI 1.0 to "SSI 2.0," which stitches discrete components into a cohesive system centered on the Verifiable Trust Agent acting as a secure digital twin and signing oracle. This system utilizes cryptographic units called "Trust Tasks" that can be combined into complex processes like community joining or KYC, while employing logical partitions known as "trust contexts" to separate different identities for enhanced privacy. The architecture supports delegated trust execution, allowing data sharing with third parties without exposing private keys, a feature critical for sectors like healthcare. Practical demonstrations showed how users could join communities using Verifiable Invitation Credentials without transferring passwords, relying instead on passkeys and DIDComm protocols, while the infrastructure itself was designed to scale into a Linux Foundation-like ecosystem capable of hosting hundreds of communities and thousands of entities.
The project's governance and operational strategy are built on a hybrid cooperative model established under Colorado's Limited Cooperative Association legal structure, distinguishing between investor members who provide capital without governance rights and patron members who manage oversight. To ensure sustainability and organic growth, the team is developing multi-tenant infrastructure using Zero-Knowledge Proofs for isolation and exploring crowdfunding mechanisms via Verifiable Trust Agents to launch multiple networks simultaneously. Technical progress includes the release of working drafts for verifiable data structures and agent names, alongside the development of a new peer-to-peer trust stack based on libp2p aimed at achieving full interoperability with existing solutions. The roadmap for the next ninety days focuses on launching the first Verifiable Trust Networks, integrating with Kubernetes and the Linux Foundation's LFX platform, and advancing initiatives like privacy-preserving biometrics and global trust registries to handle revocations similar to a DNS for trust.
Looking toward the future, the working group emphasizes that every Verifiable Trust Network should determine its own economic model, citing examples ranging from smart building conferences in New York to nature conservation projects in Geneva and Auckland. The "Founders Network" proposes a structure where founders gather peers to form circles, creating a large trust anchor that can expand sustainably through modest annual membership fees rather than relying solely on initial funding. This decentralized approach aims to counter negative narratives about surveillance technology by fostering communities with direct relationships, such as those in cities and specific industries, while maintaining control over what data is shared across networks. As the meetup concluded, attendees were designated as ambassadors to spread the message of this new digital trust ecosystem, preparing for upcoming events like the Linux Plumbers Conference where the VTI stack will be presented as a modern replacement for the PGP Web of Trust.
Read the full video transcript
Hey, hey folks. [clears throat]
Um, as is not unusual for these uh
remote locations, we're still getting
connected here. Um, welcome everyone.
We'll get going here shortly.
Um, we're just figuring out how to get
uh connected into the the screen here
at Spacian Nations in uh Geneva. So,
hang there for a little bit and we'll be
back with you in just a minute. Are you
guys hearing me? Is anyone hearing? Just
a thumbs up from someone.
Okay, you got at least at least basic.
Excellent. How's it going? Do you hear
me? Good to see you.
>> Hey, German. excited.
>> Awesome.
All right. Oh, and Andy's there.
Excellent. Andy, I know you're up late
and uh we want to get to you here fairly
quickly. We're still just trying to
figure out uh uh we want to get you up
on the big screen here. So, give it just
a minute. We'll debug this. Um get your
coffee.
All right, folks. Looks like we have um
it's great.
>> Um
>> yes, you can join in and that way we
don't have to switch back and for I mean
you can just present directly if you if
you want to.
[clears throat]
>> All right. Um, we have uh what about
seven of us here in the room and and
more folks actually on online or as many
as seven and seven. Um, I'm going to
give me a second. I'm going to bring up
share my screen and we'll get going. Uh,
have to find the right thing here.
Here we go. And this
slideshow.
Just go that
I see it's redoing that. Okay.
Share a screen.
I'm going to turn up the uh sound here
too. Okay. We're going to start here
and share
and go to full screen.
There we go.
Good stuff. This on over here.
Get that far side.
[clears throat] Okay. Is this uh is this
showing u screen showing for the folks
online?
Just a thumbs up from somebody. Okay.
Thanks, Gary. Excellent. All right.
Welcome everybody to our our first
person meetup, our one-y year
anniversary meetup. Who was actually
here in the last one?
Three of us. Okay, that's right. Okay,
some more folks are on their way on
trains. Um so, uh we'll just, you know,
they'll get here when they get here. Um
okay, let's
click here. Um
all right, so [clears throat]
it's going to be two parts. Uh we know
folks coming in from all kinds of time
zones. So whatever whatever you know
time you have to come and go. Um we're
[clears throat] going to start just
quick introductions around so you know
who's in the room, who's online. And uh
I'm going to do just a short intro to
the to the um verifiable trust
infrastructure stack and then Andy since
he's up nice and late is gonna uh talk
to us about Yeah. the uh opportunity for
New Zealand. Ah okay.
>> It's too late. No, no, you can go ahead.
We're going to we're going to get a uh
Is that an owl? Is that what it is?
>> What is
>> Yeah, we're going to get an owl set up
here for uh uh for the voice. Fantastic.
Thank you. Um and then uh and then we're
going to turn it over. So, uh Glenn and
Jeff are going to go deep into um uh VTI
Stack, OpenVTC, and we're going to do a
hands-on interactive demo. Um, is this
only for folks in the room or the can
the folks online also participate?
I'm looking over
>> I think Jeff's having network issues.
>> Do you want to connect to uh
>> it can be connected to all
>> to me? There's a USB here
and can we get to that?
>> Yes.
>> Let's see if that works though.
I know. I put it by the window.
>> Okay. And then on Zoom or Teams, you
have to connect it to all.
>> Ah, that's right. Okay. Give me a
second. We're going to try and connect
in. Okay. We're going to go to the
audio.
>> And yes,
>> that's awesome.
>> All right.
>> That's
>> Is it What am I looking for? Is it It
might not be seeing it. Uh, hang on.
What I can do is
sometimes it doesn't see it through this
thing. I'm going to try
Oops. Might need You want to pull that
just a little bit further for
>> No, it's
>> Ah, yeah. Yeah, just Yeah, right there.
Perfect. All right. Now, I'm going to
pull out this and let's see if it sees
it. If I put this in here.
All right. H You see, now it says allow
accessory to connect
and I think it's switched over already.
Um, leading owl three.
>> All right. Okay, guys. [clears throat]
We've switched over to a leading owl.
Can you hear us? Audio.
>> Uh,
uh, I'm not seeing any.
>> Uh,
oh, you Steven's hands thumbs up.
>> You got to switch the audio output as
well to this one. I'm moving.
>> Oh. audio output. Close it. All right.
One second. That's right. Um
Oh, it's on. Yeah. No. Can someone say
something if you're online just to make
sure we can hear you?
>> Nice haircut. Nice haircut.
>> All right. Got it. Okay. Thank you very
much.
>> Appreciate it. All right. Uh Okay. We've
been No, no. We're gonna go back here.
All right. So, All right. So anyway, and
uh we're going to go over we're going to
do a slide interactive VTI demo and uh
see uh how frustrated we can get uh uh
Ron and Jeff. Uh they've been working on
squashing bugs all morning, even during
lunch. So uh we'll see. Anyway, at that
point, then we'll uh uh take a coffee
break and um and then we'll do part two
um where we'll talk about first person
project, go to market, what's what we're
looking at in the next 90 days because
an awful lot happening this fall. And
then lastly, uh prep for GDC over the
next three days. Um just highlighting
the sessions we're all part of. Okay,
that's what we got stacked up here. And
now we're going to do introductions.
And uh um
is is that owl actually showing us as
well? Are we seeing the the room view?
>> You could activate the video as well.
Yes, it has video. It has 360 degrees
video cap.
>> Okay, let's do that. Hang on a sec.
Cool.
>> Uh cameras right there.
>> That it will compose the screen.
>> It's going to figure us out.
Got highlighted right there.
>> Oh, wow. It has multi focus. So, whoever
is speaking is is usually put on.
>> So, guess what that means? We're
starting with Andre.
>> Yeah.
>> All right. Nice and short. Just, you
know, basically enough background, but
last sentence. Favorite film.
>> Oh, Andre Andre Kudra CIO of Vizato has
been in decentralized energy for more
than 10 years now. I've done a bunch of
stuff with Drummond also at Sabra and
Trust IP and so on. And yeah, looking
forward to catch up on on everything
here. I have not been there for for for
a while but uh looking forward to see
what's going on. Uh favorite film uh
obviously Interstellar just rewatched it
so this is the all time best ever. So
>> good shot Jack.
>> Hi. Um am I showing up?
>> Let's see if it switches to you.
>> There you go.
>> No. Okay, I'll keep talking. Hi, my name
is Jeff Durk. I've been working with
Drummond and the FPP gang for the last
year plus now year since January or June
last year and doing a lot of the uh work
uh just uh moving things forward on
testing and helping Glenn out on that
front and we've got some uh other things
related to Kubernetes infrastructure to
help host some of the BTA and things
like that. So
>> and the credentials working group
>> and the credentials working group.
Thanks. Yeah, there you go.
>> Favorite film? Uh, that's a good
question. I'll come back to you on that
one. I'm not sure.
>> Uh, Glen Gore, Affinity. Uh, yeah,
Handbomb building lots of things around
verifiable trust, decentralized trust
graphs, and favorite film would be the
best action film of all time, Aliens.
>> Aliens. Okay.
>> Excellent.
[clears throat]
>> All right, let's go down to that end of
the table there. Okay. Uh my name is
Verstein but I come from another galaxy
which is the domain name ecosystem
>> which of course is strongly you know
related but people behave as if you know
the separate places and uh I'm
desperately trying to establish
relationships you know and you know
understanding and bridges to the
identity ecosystem. There's one project
that stands out. In our case, we work
for the sports federations for dosport
and internet top level remain run by the
sports federations. And one of the
objectives is to be able to give
identity solutions with the federation
goals for athletes and coaches and and
so on. And those are things that are
very dangerous if there are strings
attached that shouldn't be attached. Um
so um we're very much interested in kind
of learning about more ways and possibly
also to try to roll this out with a
couple of pilot projects associated with
um sports federations. Of course for
them there is a need also to find um
best current practices to do something
that they have to do by themselves
anyway because every sports federation
is actually an identity provider by
nature.
Oh, excellent.
>> All right.
>> Okay. Excellent. Um, we we we're friends
at DNS.
>> We are going to coexist and and
hopefully make a beautiful marriage.
>> Yeah. [clears throat]
>> Anna.
>> Yeah. Hello everyone. I'm also from
Affinity. Um, I'm Britney in Aid
Affinity and under the leadership of
Adam Glenn. I'm leading the the team
which is building the trust
infrastructure and my team was the one
who was building who did build the edge
page event application.
Hey everybody. Uh, Adam L, CTO for
Affinity. I report to Anna actually. Um,
um,
I'm an uh, AI slash identity
retrocomputing nerd and my favorite film
is Contact with Jody Foster.
>> Contact
Goody.
>> What was your favorite film, Emma?
>> Oh, yeah.
>> Oh, you didn't say. I didn't say but um
I have different favorite films but the
last one uh just to hint on it I don't
wear
>> Prada
>> never we
very good
>> yes you okay
>> all right I'm going to finish the last
one in the room I think most folks know
me but I am going to share because it's
really hard on a favorite film but I
think the best constructed film is
Inception um it's just earlier
[clears throat] on the other hand if you
haven't seen you you Odysius I do
recommend
okay so we're going to go to the folks
online
let's bring up uh let's see well let's
see I'm going to go to the uh this view
big view
okay Andy you're the first one up there
so go for it
>> hi everybody Andy Higgs. I'm uh
Drummond's tour guide in in the in New
Zealand. Uh uh you're all very welcome
down here. Uh happy to play that role.
Um I'm only 10 years into my self-s
sovereign identity journey, so I'm I'm a
newbie. Um
and the last film, I don't know about
favorite, but the last film I saw was
pretty good. Recommend it. Um it's a new
one, The Invite. It's a very clever film
set in San Francisco about human
connection, relationship, and trust.
So, you'll have to check that out.
Penelopey Cruz said in it, so you'll
like her.
>> Oh, yeah.
Excellent.
>> Yeah.
>> All right.
>> There you go. Uh Jerry.
>> Hey. Hello everyone. Giddy here. Uh
dialing in from Bangalore. Uh I can also
be a tour guide for Bangalore. You can
either walk or ride at the same speed.
Uh been with Affinity for a while. Uh
started with distributed computing and
then now uh really excited about
bringing the control asymmetry back uh
to the internet where we all can
exchange with more trust and
reliability. Uh favorite movie Shung
Redemption is something I keep going
back to every year. It's like a yearly
ritual. It's all about shared
experiences and I think that's what
we're here to make it better.
into the classic
and next I see Stephen Curran. He might
just be monitoring us but if not
um
>> I'm doing well. Um Victoria, British
Columbia where it's very early in the
morning. Um I'm working on uh various
W3C standards, working on DIDs, working
on DID webb and um recognized entities
um spec there at at W3C and
man that it's an early morning question
for that. But 1979, I walked out of a
theater in Toronto after the first day
that Apocalypse Now opened and was never
walked through a city so stunned after
watching a movie. So, I'll go with that
one.
>> Oh, yeah. That was
>> love smile night in the morning.
>> Yeah.
Excellent. Thanks, Stephen. Uh, Mr.
Craft, how are you?
>> Good. Um, I'll get the movie part out of
the way first. Hi, Wilcross uh with
Hams. Uh, but the the movie my top five,
I would have to say Bladeunner, the
original one, not the second one. Um,
but I can't specify exactly uh I have to
think more about which very very
favorite one. Um, we are members of the
IRA association handies very recently
through our friend Mr. Daryl O'Donnell U
hand is comes from the creative
assertions working group COG. We are a
DOI foundation registration agency have
been since 2023
and we provide we're the only uh digital
object identifier foundation
registration agency uh working in human
identity and also licensed human
likeness identity. So, we also cover um
the instances of licensed digital
replicas of humans and fictional
characters. And we uh are glad to be
here, Drummond. Thank you. We had a
great conversation you and I did a
couple years ago at or a year ago at the
uh content authenticity summit here in
New York City.
>> Absolutely. And um thank you for all the
work you're doing with with cloud. Um
super. Uh let's see. I think the last
one I see on the list is Vincent. Uh,
>> I'm not sure what time zone he's in. LA.
>> Oh, LA. Okay. So, it is early.
>> Hi.
>> Um, yeah.
I'm in LA right now. Yes. Uh, I work
closely with Jeff and we are building
this uh VTA farm platform and for
everyone else who want to create their
VTA and VTI stack easily. That's why we
are working um very hard to make other
people to easy to use.
[clears throat]
>> Fantastic.
>> Excellent.
>> Thank you.
>> All right.
Did I miss anybody? I'm I'm just moving
through folks on screen. I think we got
everyone. Um and we will have a few more
folks uh arriving as their trains pull
into Geneva. So, we'll call them out
when we get here. Um all right. I
[clears throat] want to get to the well
I want want to get to Andy here too. So
we're very quickly we'll just
I'm checking this just echoing. Um quick
intro to uh what we're now calling VTI
stack. Um you
>> yeah this
>> Oh okay. Got it. Um [clears throat]
so you for anyone who's knew this and
almost all of us are are fairly steeped
in this. Uh these are the um five
different orgs that have been involved
in in germinating this. Um
just so anyone who who you know
intersects with Daniellea Barbosa here
the the executive director of the
decentralized uh I mean LF decentralized
trust um in the context of Linux
Foundation she doesn't like us to call
it the first person project because
everyone thinks it's a project at the
Linux Foundation and it's not there are
projects at the Linux Foundation the
ones you see on the screen here plus
OpenVTC is a project LFD central trust
trust lapse but first person is not a
Linux foundation project we just use
that term as the umbrella over all this
stuff I will talk about it is a digital
trust cooperative is building a network
but the term project is just uh it's
just an umbrella term we've been using
since the outset and Daniel said well
it's okay if you keep using it just to
make sure people understand it's not
Linux foundation project by itself um as
a result of that project and the
collaboration among those groups We did
start a working group at trustedia last
September decentralized trustcraft
working group. We'll be talking about
that quite a bit. It is a joint working
group of trust and diff. So um um anyone
joining was part of either one of those
um part of that um and just just so
everyone you know knows what we're going
to talk about here today now being
called the VTI stack our public trust
infrastructure um is based on the trust
stack and that's been under the way for
seven years we're going on our seventh
year six [clears throat]
months Andre was one of those folks who
was there from the start Um
uh [clears throat] anyway, Stephen early
on Stephen helped us figure out the four
layer stack um diagram there um
[clears throat] that I think everyone's
familiar with. So, and I think folks are
also familiar the whole key to the four
layer stack is the spanning layer. um
the TCP stack that's the IP layer and
with trust RP it's the trust spanning
layer which gave rise to the trust
spanning protocol PSP which you're going
to see
I don't actually know if that's going to
be what you're seeing live today or
whether it's home
doesn't matter right
>> doesn't matter
>> that's it then we'll go into that okay
so the last thing I'm going to show is a
slide I've been using um starting in uh
uh last March when I had to a talk uh at
uh the quiet open AI, excuse me, quiet
um personal AI uh conference in March
and I needed to summarize all of what
we're doing for an audience. I had 20
minutes for the whole talk. So I I drew
this picture. I said this this is a way
to think about this. So we start with
keys. everything about it including PGP
web address is all based on
cryptographic keys. Okay. Um and if we
care about quantum proof you can even
address that. It's all based on on the
mathematic keys. And next up is trust we
call verifiable identifiers because that
includes both dids and uh autonomic
identifiers aids which is what carrier
uses which can be expressed as a did
like the web s but doesn't have to be.
That's why we use that and then of
course that leads to verifiable
credentials.
Um now the reason I build it this way is
I draw a line and point out those are
the core elements of what referred to as
self-s sovereign identity and they
wanted me to bring down yes this is this
is this is what we've been building.
This is what they are currently
implementing down there. Andy will talk
more about that uh digital identity New
Zealand and what it is established
digital wallets as the sort of core tool
is going to be necessary for this new
decentralized identity solutions.
Now
what I explain is that got us halfway
there. Okay, these are essential tools.
We have to have it. But it doesn't
actually build out interoperable digital
trust infrastructure especially at scale
and especially with the network effects
we need. And so what we've been building
now decentralized trust app working
group in the first person project is the
next layer up and it starts with
verifiable trust agents and this is what
you're going to see um Glenn and and
Jeff demonstrate in in depth
[clears throat] with these um and this
by the way does not have to be an AI
agent. It can be an AI agent and we and
and one node in the graph can definitely
AI agents but every node in
decentralized trust graph has a
verifable trust agent and they all
communicate and do work by trust task
which Glenn's going to talk a bunch more
about
those now composed into verifable trust
communities any group any size any place
any reason and those can compose
communities can have communities and oh
interest color in the way it's coming
across the industry
and at full scale those communities
imposed into verifable trust networks
and that
first person project it goal first
person network first person cooperative
is always been a verifable trust network
of networks
and so the point I make is that is
covered up there in that corner because
again I know I'll put this up
for a second. Move that over verifiable
trust infrastructure. Now you look at
the whole stack and the big the big
conceptual um shift is that now it's not
just about digital logs. It's about
digital agents of all kinds including AI
agents. I'm looking at Adam and Anna
because Glenn keeps telling me that's
your big and you're going to show me
some beautiful things here in the next
couple days.
Ah, so um that's
>> Yes, we are.
>> There you go. That is the uh the intro
that I now use for this. And uh Andy can
tell you more about In fact, next up is
Andy because it's I don't know it's 1:30
in the morning for you now, Andy. Is
that right?
>> It's 20 to midnight, but it's it's fine.
I've been on European time today. Not
really. Yeah. No, I'm I'm good. I'm
good.
>> Good. Okay. Well,
>> with you in spirit, Drummond.
>> Yes. [snorts]
And given that time, I would put you
down in this uh corner of the screen.
We're seeing up here. Um, uh,
I I wanted folks to be able to meet Andy
and vice versa because he did host a
fantastic 10 days that I had done in in
um, New Zealand in first two weeks of of
August and it totally opened my eyes as
to what the opportunity is in New
Zealand. But no one can talk to this
better than you, Andy. And uh, I
previewed just a handful. I picked out
some of the slides uh that that uh so do
you want to just give folks uh again the
short overview one question I do timing
>> good yeah good
>> okay but Andy's got
>> okay all right Andy go ahead and I'll
just uh I'll just uh you know bring up
slides as as you want me to um I'm gonna
start with this one is uh just shot that
he shared in the newsletter um of the
keynote that uh um uh that Dr.
Keratiana, what's his last name? Um
>> Tyuru.
>> Yes. And maybe tell tell a little bit
about why we did this joint keynote,
Andy.
>> Yeah, sure. Drummond. Hey, and thank you
so much for this opportunity. Uh there's
so much to to share, but I'll try and
keep it keep it brief. Uh I love this
photo. It's not just because of the
green queen and the match of with the
backdrop with the the drapes, but uh I
just think Drummond it just sums up his
trope. He like a kid in a candy store.
He's enjoying the conversation with um
his new um fast friend Dr. Karatana
who's a kind of leading academic down in
New Zealand on sovereign AI, ethical AI.
Um and you know this is their first time
together and they they really did did
gel. It was a joint keynote because we
were trying to make the actually
Karatana was one of the biggest um
not was more of a he called us out the
previous year for the hoie talking about
Marti and Marti um T Marti values the
world of Mari their values which are
very much universal
values to to be Mari is to be human and
at the core of that is um mana mana and
mana aritanga which is kind of re
respect for humans and um you know
respect for human dignity and your your
humanness
and uh we were talking about these
values but we didn't have that many well
any MAI on stage apart from those uh the
MC and those doing the the blessings. So
this year we wanted to put Karatiana at
the heart of the conversation and it
really uh went well and I think the
penny dropped for Drummond
uh cuz we've always sort of said hey
identity is just going to be like
payments and um there's going to be a
few trusted brands out there and we'll
just decide what brand we trust. But um
that's never really felt like the right
answer. And I think this is Drummond
realizing that the right answer is um
that there's no um network that's more
important than another. We're all sort
of sovereign within our communities and
you know we're all of equal standing.
And I think if if we get that right, I
think it's um it's going to go a long
way. And I just want to call out the the
the sport um example that came through
before because you know it's like a
club. Clubs are at the heart of this and
sport is really the heart of the
community here in New Zealand and we
love our sport. And interestingly the
sports fed federations down here,
the major ones like like rugby, they
they've managed they've got this data
sharing agreement where they've retained
the rights of the data to the to the
players and they still haven't figured
out what to do with it. So, I think
that's a really good um early use case
um because, you know, they're all trying
to figure out how to um you know, stay
afloat in this this new era where you're
not allowed um well, you haven't been
allowed t tobacco sponsorship for a
while, but no alcohol sponsorship and no
gambling sponsorship. And so, you're
going to have to reinvent and it's being
harder to balance the book. So, I think
there's definitely something there. But
this was our um we called it our north
star but it really should be I got
called out it should be our southern
cross the the star um constellation in
the in in [laughter] the southern
hemisphere is southern cross. So um the
uh toa no um mahu tonga mahu tonga but
yeah it's decentralized trust is our is
our southern cross and um yeah we sort
of set out there's really three options
and I think all options will be uh
adopted to varying extents. I mean the
smartphone has the the huge advantage
and um Oracle and their wisdom have
become the most open decentralized
company we we we all know of and they're
very very dominant in New Zealand across
uh banks and um other corporations but
um she just did a post on LinkedIn about
the the mini mini Mac mini um trend for
and even um you know Palanteer one of my
good buddies was at Palanteer uh for
many years and I give him a hard time
but even Alex has started calling out
data sovereignty. So um it's the is the
issue of our age. So I really think um
the time for the decentralized trust
graph has come and for all the reasons
we've got here you know community
ownership privacy by design all the rest
of it dignity really at the heart that
idea of mana manaka
um and may maybe that's the sort of
trust model which I think has definitely
earned its place and you know to me it's
not about brands anymore it's about you
know implementing that at scale and New
Zealand's always been a great test
market because it's 5 a half million
people and two islands but there's
nothing really more to it than that I
mean we do have a trust framework which
is live uh so that enables this um
decentralized trust model um but we're
still pre-implementation because the
self-determination values are so strong
here no one really wants a big brother
ID everyone so even the word digital ID
is is is you know I get I at um death
threats as I'm sure some of yeah anyone
who doesn't understand what we're trying
to do doesn't isn't a supporter and I've
just been at a crypto conference in
Queenstown and they're like look we
don't want digital identity and I was
trying to explain where you guys have
got to with decentralized trust and they
said well if that's true maybe but you
know we really don't like this idea at
all [laughter]
so yeah we've got to do a better job of
explaining it um do you want to go to
the
>> you use this slide to summarize the
>> Yeah. Well, it was funny because there
there are a lot of a being Queenstown.
Queenstown's actually in New Zealand,
but the Australians um think it's part
of Australia, which I I like to joke
with them about because um it's like a
principality. It's like Daros and it's a
beautiful place and it's like too good
for to be New Zealand. So, it's actually
part of Australia. About 65% of the
expenditure there is Australian. So, we
let them think that because we want
their their tourist dollars, but um so
someone said at the conference, "Look
guys, you just got to you've just got to
um you're never going to be a price
maker. You're going to be a price
taker." And just just just copy us. And
um and we'll show you how to do aic
identity. And and I was doing the the
talk on aentic identity. And I said,
"Look, I think we can be a prize maker
actually." and we we we're going to work
with the guys at um First Person
Cooperative and and you know hopefully
you know we can be early and um we can
we can set our own commercial terms for
this and this was a slide um it was
really the bridge you know we we need
some catalytic funding but the 30
million number was just a number really
just to say look if you're serious this
is sort of what it's going to start to
get going but the potential and this was
more of an opportunity across Ross, you
know, all of the the um extractive um
capitalist kind of models or not models,
more um platforms, you know, from banks
to big tech to everything else that's
that's taking value out. And uh I mean,
I think even Alex Karp has said, look,
if if you guys don't take control of
your data, the world's going to be run
by two and a half thousand people in
California, you know, which is not a
good scenario for the world. So um you
know once people realize that and we had
um Dr. Premod Varmmer from India the
chief architect of the India stack
talking to us once they understand the
power of the unbundling from the
platforms and you know this opportunity
to put in place this new infrastructure
you know 30 billion is 10% of our GDP
McKenzie already said it was digital
identity on its own was worth 3% but
when you take that didn't allow for
agentic systems and um you know uh open
marketplaces um once you bring those
into the thinking
um by the end of the conference and of
our conference the identity conference
that Drummond was at people were saying
yeah we can get to 30 we can see there's
a $30 billion opportunity here so um
it's not so challenged anymore that
that's just a really high level business
case and I think that's it's actually
important for Drummond and and your
mission because you know you've got to
paint the picture of this is a big
opportunity that's broader than just you
know streamlining workflows this is
about you the value of our of our data
and creating new types of open um
marketplaces where people's ideas are
very valued and and and Dr. to promote
really spoke to the um the small
business owner, the entrepreneur, the
startups and talked about the tens of
thousands of startups in India building
on the their sovereign stack and you
know we don't really have a fintech
industry in New Zealand because you know
the data is not open you know even
though they've been pushing open banking
for a long time it's it's still hard
going and you know they're forced to do
screen scraping and everything else. Um
the the other thing that's helping us is
every single proprietary system they've
tried to implement at government level
has been a complete flop. So it's
becoming criminal. The level of um you
know tech investment that is going
nowhere here. So you know we're we're
now pushing this as hard as we can
despite um the resistance. Uh and this
the next slide Drummond. Okay. So this
was the um this is our current our
current reference architecture which is
um something we've been working on with
with government with it was the DIA the
department of internal affairs now the
government digital delivery agency GDDA
which hasn't delivered anything yet so
I'm starting to call them out for their
failure to deliver but really they just
haven't moved with the global
you know developments and identity which
um all you folk have been so um strong
on. So um this was kind this is kind of
where we're at with our um uh reference
architecture. But if you move to the
next slide, Drummond, this was um one of
our leading architects here in New
Zealand who's actually also an
accredititor under the trust framework
said this reference architecture needs
to evolve to this stack which is really
the um verifiable trust infrastructure.
you know, the the decentraliz trust
graphbased stack. Uh let's call it the
sovereign stack cuz that's what we call
it when you're in New Zealand, Drummond.
and uh you know we've added verifiable
trust agents in there and um yeah
relational identity um domain specific
governments uh membership that I think
that's such a an important point because
you know to be accredited under the
trust framework you really need um well
you need to prove the trust and the
longevity which if you work with the
right organizations who are already
doing this who are already trusted I
think that's where you where you can
scale Um and then of course
>> and then yeah this was another one that
sir he he had done a whole plan around
decentralized identify for the health
sector working with health New Zealand
but now he's added all the other ones
cuz now he can see how if we get the
foundation right we climb the right
mountain because I keep saying we've got
to make sure we're climbing the right
mountain and you know is it M dos or is
it you [clears throat] know jotss or is
it something else um and of course it's
probably all of them but you know you
need to get the foundation right around
the key. Um um well the the yeah the
diagram that Drummond just saw which
really landed well for people here
um and um and then as you move up the
stack you've got this opportunity and
where it really um comes alive is is
across the use cases and so we're
working with Trust Alliance New Zealand
which is the agri use case and they're
very keen to see it scale. Education's
starting to move, although they're quite
conservative and educational
institutions.
Um, you know, the banks are starting to
realize they because of the scale of
fraud, they have to do something. So,
yeah, the timing is all lining up. We've
actually got an election in November.
So, you know, nothing's going to happen
this side of Christmas, but, you know,
the new year, I think, if we we want to
be really ready really to accelerate
adoption into the new year. So, if we
can get some pilots done this year and
across some of these use cases, I think
we'll be in good shape um for 2027. Um
is that is that enough drummers?
>> We just had a couple more folks uh join
uh we just finished. This is uh Andy
Higs who's a the executive director of
Digital Identity New Zealand. He was a
host of the trip that I took down there.
Um and I just he's he's just been giving
us an overview of sort of the
opportunity down there. Uh we can share
the slides later. Um but I just want to
say anyone anyone have any questions uh
for for uh Andy uh before we go live on
it being 1 in the morning hearing.
>> All right. It's I think Andy, thank you
so much for taking the time to uh share
all that. Um I don't know how much
longer you want to stay on. Uh we're
going to go.
>> No, I'll stay I'll stay for a while.
Well, I'm really keen to see the demo if
we can. Hopefully, that was useful. I
really thank you for the opportunity. I
wish I could be there. So, it was uh it
was really good to
>> Oh, well, I mean, what Andy really wants
all of us going down there for the uh
the next two week. So, uh that that's
the his his secret plan.
>> Well, no. Yeah. Well, we need all the
help we can get because um you know
although there are a lot of open people
who are you know can see this is the
right answer, there's also a lot of
incumbents and a lot of uh a lot of
resistance which is another reason why I
think people think New Zealand's a good
opportunity because it's small enough to
um yeah to to and and there's kind of
two degrees of separation down here, one
degree to two degrees. So everyone knows
everyone and uh you know we think that
if you can get the um you know some
momentum you could actually implement
this at scale across multiple
industries.
>> Absolutely. Excellent. Thank you very
much Andy. Really appreciate all that.
Um
next well first we'll quickly let folks
that just joined uh do we we we've done
one round of introductions. We we'll
wait to break and you can meet everyone
else. But at least the new folks that
just came in. Uh we're using this owl
here. So speak to the owl and just uh uh
say hello. Um we're also asking everyone
to name their favorite film.
>> We'll start with you, Darl.
>> Daryl, executive director of IRA. Um
Armageddon.
>> Armageddon.
>> Read into that what you write.
>> Exactly. Sometimes you need cheese,
[laughter]
>> right?
>> I'm I'm brazed. I'm a little dehydrated.
Uh I think I think for this context I'm
the executive director of GIF. Um and I
invented something called verifiable
community and I'm surprisingly
gladiator.
>> Gladiator.
>> I think it's just an inc like it's the
first time I understood what male
friendship is about [laughter] because
I'm I'm not male but like there's
something really deep about what male
friendship is about that comes out in
that film. Excellent. By the way, there
is water on the table right behind you
over there.
>> Yeah, I got some very overpriced
electrolytes if anybody else.
>> Excellent. Daniel.
>> Oh, I'm Daniel. Hi everyone. I'm Danny
Glint. Uh I run a small consultancy in
AIS. Actually, that's what we do right
now. And I'm also part of BIF running
there. So, and then what was the last
thing I'm expecting?
>> Uh your favorite film.
>> Oh, favorite film? I don't know, but
probably a recent one. The Invite. I
don't know if you've heard that.
>> It's a new one. It's quite a cool film.
I recommend it.
>> What's it called?
>> The Invite. It's about the invitation
for a dinner that goes sideways.
>> Yes, it's one one of mentioned that
earlier.
>> That was my one that that's already been
taken. Sorry about that.
>> [laughter]
>> Uh yeah, Mitchell Travis, I'm a privacy
and decentralized AI researcher and my
favorite film probably The Fellowship of
Ling.
>> That one New Zealand film there.
>> Yeah,
well there actually when I was in New
Zealand I saw someone dressed up as
Gandalf walking around Christ Church. So
>> that's pretty normal.
>> That's [laughter] true.
have a regular day probably.
>> All right, I'm just quickly going to uh
for folks that are come later. So, we've
done introductions, just did a brief
intro to the public trust in stack and
then Andy uh just gave us his his
overview of New Zealand, the opportunity
there. Um and uh and now we're going to
uh the balance until we get to our uh
coffee break is going to be these two
gentlemen here. Um uh showing uh the I'm
going to stop sharing and turn it over
to them. uh just
this is our our deep dive interactive
demo of open VTC in in preparation for
maybe we'll explain a little bit about
that um a month from now almost exactly
to the day right now I guess a month and
couple days we're going to be in Prague
at the Linux uh plumbers conference
that's their annual conference of the uh
kernel team showing them this as uh the
pending replacement for the current PGP
weather trust. So, no pressure for these
guys. Um I will go to uh
not
I guess I I'm the one to go.
>> There you go. All right.
>> We are just
little the window. There's one on the
left. All the way.
>> That one. Yeah, exactly.
>> There goes.
>> There goes New Zealand. Uh, sorry, we
won't find any Australian, New Zealand
jokes. Uh, as you go through this,
welcome everyone. Uh, I'm Glenn for
those that just joined. If you haven't
met before, uh, this is going to be as
interactive as you want. Um, please
interrupt at any point in time. If you
have questions, something doesn't land,
uh if you don't believe what I'm saying,
and you should not believe what I'm
saying at any point during this session,
just jump in. It's part of this is
actually some of the practice and
pre-work for the plumbers conference
that Drummond was talking about. And
there's going to be a whole bunch of
super brains in the room, but they've
never seen anything to do with
decentralized identity before. Uh
there's a lot of stuff not in this deck
though as well. Um so just because
Mitchell's in the room, there's a whole
bunch on ZKP that we just don't touch on
because until it solidifies a bit, it's
just confusing [clears throat] and
distracting to everyone where you may
hear something that may not uh go as you
go through it. Um all right, let's jump
into this. So
you know the whole premise of VTI stack
is that every entity and when we use the
word entity entity can be a human, an AI
agent, a building, a transaction,
uh a business, they all actually need a
digital twin that represents themselves.
And this digital twin is effectively
your shadow self.
Jung use a different word but uh in
terms of just how you represent yourself
in an online world. Um and the thing is
you actually have digital twins today.
You just don't know about them and you
don't have control of them, right?
Facebook has one for you, Google has one
for you. Apple has one for you. Amazon
has one for you. You probably have about
400 of them out there and they're all
fragmented. And this is part of the
problem. If you think about the sum of
the world's information, it's heavily
fragmented and you can't get a single
holistic view of that for yourself. But
that is also true for communities. And
again, you know, building on what Andy
was saying in New Zealand, in Australia,
First Nation tribes have exactly the
same challenge, which is they don't own
their own information. you know, it's
being given to the government and
universities who then monetize that data
uh on behalf of the First Nations
people. They don't get to monetize it
themselves as they go through it. So,
this is really what this stack evolves
uh solves. You'll see there's two themes
mixed into this. I will try not to talk
too much on the AI side of things, but
this started from helping people, but
really the reality is we are all heading
towards a future where you're going to
be working side by side with AI whether
you like it or not. So you might as well
jump in with both feet and actually give
proper structure, authority, consent,
approval to AI from the start instead of
us repeating the mistakes of kind of the
content platforms of today and just
giving it away. Um there's really kind
of two things that we talk about. One is
there's identifiers that you control.
That's when we talk about a graph that's
the node. And then there's the
relationships that you have and you form
with people. Relationship with a
company, relationships with other
people, relationships with a device,
relationships with websites. They all
get represented by edges on the graph as
you go through. So I'm a member of a
community, I know this person, etc. Uh
the digital twin is not a profile. I
just want to make this really clear
because it gets um confusing sometimes.
your digital twin. It's the graph of the
relationships that you form over time
and what those relationships start
collecting because you start collecting
a whole bunch of credentials and meta
data as you go through this. And you
know these relationships must be
portable.
They travel with the parties. They don't
travel with the platform that you're on
as you go through. They have to be
reciprocal.
I would love to say that I know I don't
know who's someone cool right now. Uh
doesn't matter. I know Drummond. But if
Drummond doesn't say something back
saying I know Glenn, it's not worth
anything, right? I could know whoever
Peter Jackson,
you know, unless there's a reciprocal
reaction there. It's just a one-way
statement. Uh these things have to be
revocable. I know Peter Jackson. He
knows me. We then got in an argument,
had a falling out, and now he wants to
revoke that relationship.
It has to be composable. So, one of the
things that you have to do is take all
of these credentials and be able to
construct the graph from the
credentials, not the other way around.
Uh, a lot of platforms will manage the
graph as a database and then construct
credentials from the graph. And the
problem with that is someone's owning
the graph and they're claiming ownership
on behalf of a network as you go through
it. This is the kind of other way around
as you go through this. Um, yeah,
whatever. We're going to go through some
of this. Uh, I will say, and I know some
of you have been in this industry for a
while, so here's I do say some
provocative things sometimes. I think
the original philosophy of SSI, it was
great. It did its job, but it's also
failed. Um, it did not drive the change
that people wanted.
But as Newton would say, we all stand on
the shoulders of giants. This really is
kind of kind of ter like it's SSI 2.0.
It's standing on the shoulders of what
SSI1 did. Uh so it's just a better
implementation, a more pragmatic
implementation
and really the focus is stitching a lot
of the discrete components because part
of the failing of SSI you had people
solving DIDs but not talking to the
people that were working on verifiable
credentials, not working with people who
were doing messaging, not working with
people who were trying to create you
know the first registries of this. So
you ended up with all these wall gardens
and you know what really to me brought
this together was actually your first
person project white paper Drummond uh
which really just brought a lot of this
together and the concept of the
verifiable trust agent was just a
no-brainer of it's one of the missing
pieces of the architecture as you go
through this and my background is
architecture so you know if you don't
get the design right uh good luck
building code to it or anything else as
you go through it. So what we're
building is the VTA, your digital twin,
the VTC, the trust community, which is
uh managing the policies, the
governance, the collection of people,
and then we're building the ecosystem
around this as well. But we also have AI
agents working in there. And it's crazy
what we can do with some of this
technology already. And we're just at
the very start of it. uh none of what
you're going to see existed
in January of this year. So this has all
been built in the last six months. And
to kind of just give you an idea of how
driven the working groups and the teams
are on this, there's, you know, many
different DTG working groups on this.
There's uh DID groups that have uh
tapped in to help with some of this.
But, you know, you're talking over 4,000
commits, 24 repositories created. Um,
huge millions of lines of code already
as you go through this. Uh, it's just
crazy complex. Um, very cool as you go
through it. But what we're seeing is now
that a lot of the foundation is built,
building on top of this is much easier
as we go through it. Um, while we're in
Europe, I think it's always good just to
give a contrast.
People sometimes ask, does VTI replace
things like EUDI, IDAS? No, it doesn't.
They're kind of two different approaches
that coexist. There is and always will
be a model where governments want to
have kind of state driven identity,
state driven credentials. Uh, they will
publish that. Um, they have certificate
authorities. It's accredited. There's a
whole bunch of things and for good
reason, right? A driver's license allows
you to drive a car on the road and can
be internationally recognized. Your
passport gives you the right to uh cross
borders and that is universally, you
know, kind of recognized by people as
you go through it. The wallet consumes
trust. It's a presentation of a
government credential. It's actually not
a vouch. The government's not saying
you're a good person. They're not saying
you're a good driver. They're not saying
you're going to be a good tourist as you
go across those boundaries. Uh that's
the limit on VTI. It's driven by the
community. And by the way, you can be a
community of one at its smallest. You
have many devices. You uh have
relationships with those devices. Sounds
so weird when you say it that way
sometimes. Um there's kind of trust data
which is queried live. And so a big
piece of these are things like the trust
registries. And the trust registry is
what keeps things honest. I've given you
a credential. I can't take the
credential away from you, but what I can
do is update a trust registry and let it
know that it's revoked or there's a
something has changed on that as you go
through. Uh the anchors are the DIDs
themselves and the keys in those DIDs.
Membership is based on the governance
and what it means to be able to join a
community as you go through this. And
the community itself is vouching for its
members and kind of publishes the roster
if it wants. So a community can be
public public something like the Linux
kernel for example but it can also be
private
and if it's private it may not be
recognized by any other community. Uh it
may be private but only be want to be
recognized by a limited number of
communities. That's their right and they
can do this. And a question that comes
up a lot is, well, what happens if
someone creates an a hate group
community? Um, how do you stop that? The
simple answer is I can't stop it. If
people want to create a hate group of
whatever that is, go for it. But what
will happen is that hate group would be
very unlikely to be recognized by any
other community or group that doesn't
subscribe to the same philosophy. So the
idea being is that you kind of starve
out the relationships or the graph of
responsibility and this is again where
things like accredited trust networks
will come into play which is you know a
trust network for health care is
unlikely to recognize a group that might
be I don't know antivax for example uh
if the government has a vaccination
status would be a good example of how
that works. Um, so they don't replace
each other. They I think they work
together uh as they go through this.
It's really VTN's or the verifiable
trust networks and the verifiable trust
communities. They're very much a
federation or a fabric of what they
choose to do. By the way, there's not a
single VTN.
First person project can define a VTN
that they will vouch for what it means
to be a member of the first person
network. But I can go create a
competitive network and see if I can
curate a better list with a difference
governance policy as we go through this.
And this is where they start to stack
up. And a community may choose to be
part of the FPN and the GGM.
Register that name now as you go through
it. Um, so there's a lot of flexibility
in this, but that's also where some of
the complexity
uh comes from as you go through it in
terms of, you know, kind of a a trust
stack. I just realized people at the
back of the room can't see that. If you
join Zoom, you can see it on your screen
easier. Uh but the biggest thing about
it is at the lowest level is the
foundations the DIDs the keys trust
registries witnessing infrastructure
kind of you don't really need to see
that on a daily basis then there's the
trust spanning layer on top of that
which is things such as the asynchronous
messaging systems that it use relays
delivery and we'll talk a little bit uh
about that then there is something new
called trust tasks so
before we started down this path, you
know, didcom was a messaging transport
that had built in it not just a
messaging layer but also the start of a
protocol layer uh which worked well but
the problem is it was didn't work
outside the world and you start using
TSP tsp uh infamously went we are not a
protocol layer wheelie but uh neutral so
trust task is effectively now a
cryptographic way of between two parties
saying, "Adam, I want you to do a task.
Here's the def definition of that task.
Everything that is needed to complete
that task is within it." And then Adam
gives a cryptographic response back
saying, "I either uh completed that task
and here are the side effects of the
task or I've rejected the task or you
know there's a next step you need to
do." Uh very very simple. There's 350
trust tasks defined already. uh they're
extremely strong. One of the things in
the decentralized trust group is they
have a risk and harm prevention uh kind
of research team and doing systematic
reviews. It's being focused very much on
these trust tasks and looking at you
know how they work. You then take those
trust tasks and create trust ceremonies
out of them. So trust ceremony is
if I need to stitch together more than
one task to do something like joining a
community well I need to do some KYC I
might need to check a few other things
that is a ceremony we'll talk about that
credentials consent and then at the top
of this are the the applications open
VTC which is the CLI tool that Linux uh
kernel developers will use there's agent
memory MCP bridges uh AI tooling
whatever it is that you want and this
kind of loosely follows the trust over
IP model as we go through it.
Um and we kind of talk through that. So
one of the big things we did was there
was a workshop in January February uh
some of you around the table and online
were there and we realized that while
there's a lot of standards and
specifications
there was very little that was working
across it and people who had been trying
to build across the standards you just
run straight away into incompatibility
issues and so we decided that what we
needed to do was build the code at the
same time the specifications are being
drafted and worked on. And in hindsight,
yes, it was the right thing to do, but
at the time is a little controversial.
Uh people were not fully convinced on
it. Um but I would say that what has
happened from as we build is it's not
that the build is ahead of the specs.
It's not that the specs are ahead of the
build. They're kind of doing this all
the time and moving around. But what I
love is that we're getting evidence
of where the specs are really solid and
absolutely helping clarify things, but
also where they just simply don't. Uh
I'm not going to go into the details,
but if you're on any of the working
groups, you'll see there are issues
galore being talked about, PRs happening
left, right, center, and that's good.
That's what you want to see in a vibrant
community. uh some of those communities
were pretty dead before this occurring.
They' kind of been frozen in time uh as
you go through this. So
let's see have a look here. Uh this is
kind of some of the examples of what you
can do uh based on this. So
one of the concepts of your VTA is the
VTA holds your keys and it holds your
credentials and can hold kind of meta
data. when that VTA is working on your
behalf,
it's not handing out the keys. Um, you
can sign, you treat it like a signing
oracle. You can kind of hand it
information and it will generate the
signatures for you, hand them back. Um,
it can enroll and revoke devices that
you connect to the VTA and therefore to
other aspects. Um, there's a lot of
really fun things in there that you can
do with the VTA.
the what it actually holds is a whole
bunch of information. So, your VTA is
holding all of your key material uh and
signing keys and you have control
whether they leave the VTA
or
as in they don't leave the VTA or
they're actually going to be given to
certain applications and services as a
proxy as you go through. So, I'll show
you how that works with Open VTC when we
get a demo. Uh it's a credential store.
So it does all the things, issues,
holds, presents, and revokes your
credentials. Uh everything you expect
there. It's a secrets vault. So again,
we want to kind of shift left and work
with existing website. So it can be a
password manager for you if you want. Uh
it has agent memory. So you can actually
tie your AI agent to your VTA VTA and
use it as a durable secure store for
your AI interactions. uh which is really
really powerful when you take that
capability with a VTC you can create AI
community memory which is really
powerful so this one of the things that
we want to unlock whether it's before
Linux uh plumbers event or afterwards
but imagine the DTG working group had an
AI shared community memory that had all
the specs latest decisions being made
everything in one place so that when you
join that and you say I'm going to use
an AI agent to help just distill and
explain things. That AI agent instead of
trying to figure it out on its own is
now talking to the DTG shared or memory
as you go through this. Uh, a lot of
people ask, how do we move so fast on
the build if you're kind of looking at
the build site? That's part of the
secret right there is everything is
going into my VTA memory for myself and
my agents work off it. Uh, it has
application state. So, one of the fun
things, if you've ever uh configured an
application, then you lose a device and
you think, "Oh crap, I didn't back up
the application. I've lost that aspect."
The VTA can do that for you. Uh it has
approval policies. So, a big thing
you'll see on the VTA and VTC is
everything is policy driven. And when we
say say policy driven, it's open policy
agents, OPA. And one of the things we've
done is taken the policy management and
pushed that into the approval chains. So
for the first time
you can have intelligence as to
depending on who is asking for an
approval and what the trust task they
need approval for I can handle that
approval flow differently. So again,
this comes from the expectation that in
the future,
you don't want to wake up in the morning
in an AI world and say, "Good morning,
Glenn. You have 123 things to approve."
Right? That is what is going to happen.
It's going to be GDPR all over again.
Approve all cookies. Just click, click,
click, click, click. Right? So what I
can do is I can say actually my VTA, you
are allowed to approve some things that
are low risk on my behalf. I may plug in
an AI agent to deal with things that are
of medium risk. And then it's only
certain critical things that meet the
policy criteria I set that comes to me
asking for a human intervention. The
idea being if I only get asked once a
day, once every two days, I'm going to
pay a lot more attention to it than the
100 plus approvals a day if we kind of
do this. And again, this is really
powerful. This also works by the way in
the VTC. So really good example here are
things like a family unit. As a parent,
do you want to approve things on behalf
of your children? You can start
programming that. For example, do you
want to approve things on behalf of
elderly parents that might be at risk of
getting scammed? You see an unusual
financial transaction. You can program
the approval to be, hey, all of the
kids, the adult children, if three out
of the four approve it, then it's okay.
So you can really do a lot of fun things
with this consent management, device
agents, uh identity and operations with
this as you go through. So uh lots and
lots of things you can do with it. Uh
one of the questions that comes up a lot
is well what about in the VTA? Do I just
have one identity? No, you do not. You
have uh trust context. Trust context you
can break up however you want. This is
just one example. I can have my personal
IDs for Apple, Google, Facebook. Each of
those is a context. What that means it's
like a logical partition. They can't see
each other.
And I can start doing policy saying
anything in personal always keep
separate from work. Apple can't see
Google. Something at the personal level
can see Apple, Google, Facebook. Uh you
can really do whatever you want there.
This makes it really easy by the way. If
you sign up to like a new site or a new
application, you just create a context
and if a 24 hours later you don't like
it, just blow the context away.
Everything gets shredded with that trust
context when it goes away as you go
through it. Uh this also means by the
way you can have multiple VTAs. So you
don't have to have one VTA doing
everything. You can have a mesh of VTAs
and there's actually a fleet management
tool uh that helps you manage that. And
so you can start spreading out the trust
context across a fleet of VTAs uh if you
want. Um just be warned, it gets very
very complex very very very quickly as
Jeff and I will attest uh on some of
this. You'll see a bit of uh a multiVTA
demo as you go through it. Uh the
verifiable trust community. This one's
really simple. Uh a community owns its
own policies. We will have out ofthe-box
policies that allows a community uh to
get started, but they get to choose what
it means to join. Must have proof you're
an adult, must be in Switzerland, must
be a member of DI. Sure. Whatever it is
that you want, you get to set. Uh that
is set at a policy level. Then there's a
policy engine that runs all that for
you. Uh as you go through the trust
ceremony, there are side effects
created. And those side effects are
things such as you got accepted and here
is proof of that by a verifiable
membership credential, a verifiable
endorsement credential. Uh the VRC's the
relationship credentials you create
within that community
and people outside that community if
they want to ask you know Glenn are you
really working on the Linux kernel
project and if so are you a contributor
or are you maintainer or are you a core
level? Well that's where the trust
registries come in. You can ask the
trust registries that every VTC has for
that type of information and they get to
choose what goes in those trust
registries, who can talk to the trust
registries, whether they're truly public
or you must have a credential saying
you're recognized by the trust network.
Uh so a lot of this uh is all here. All
of this runs on DIDs. If you I just find
it amazing that even in our own
industry, people still don't understand
really what a DID is. So again they
really do three things and you must
understand these three things are the
entire backbone everything in BTI works
on first of all it is the unique
identifier they are globally unique
second they are what holds your public
key infrastructure
proof of ownership is sign something
with the key in the if you can't sign it
you don't have ownership of the DID as
simple as that the third one is what are
the service endpoints how do Do you
reach me? How do you talk to me?
Anna, do I talk to you using Ditcom or
REST or uh TSP? Do you have a trust
registry? Are you a community? Are you
an individual? All of those details are
the service endpoints in your DoD
document. Uh as you go through it, uh
the ones we support by default, you can
kind of see there the usual suspects. I
will say for us did webv is unashameably
the star of the show. Um it's designed
to be you know highly highly durable. Uh
it's verifiable history because and
you'll see this there are already that
we are using in this stack that have got
hundreds of changes to them as the keys
are getting rolled service endpoints
change etc. And webv just works
beautifully. chef's kiss. Uh, and it's
extremely performant compared to other
did methods that try to do this uh, as
you go through it. So, I think Stephen,
you're on the call. Thank you. Uh, great
protocol. Uh, as you go through it, um,
things are ced with a DID. It's okay.
Um, you can have this kind of immutable
methods like DID key. If you want to
change the key, it's an entire new DID
with a new identifier. or it can be
mutable like webvh uh and others that
you go out there. I will say that u if
you want to work with a vti stack
there's kind of a few core protocols you
must support. If you can talk did webvh,
you use curve 25519
as your cryptography algorithms and you
can talk didcom or tsp,
you can fully interact with everything
in the vti stack. That's the basic three
things you need. If you don't have those
three things, it's just another walled
garden and you can't uh talk to it.
Everything else is built on those
fundamentals uh as you go through it. um
in terms of then uh how transport works.
So there's your one VTA for simplicity,
there's the trust tasks which really
kind of define how this works and I'll
send some links out for this. Uh but how
you transport the information across, we
actually don't care. uh it can be trust
spanning protocol it can be didcom v2 it
can be rest there's lib ptp coming uh
these are just different transport
mechanisms that work and this is being
used right now when you see the demos
you'll see divid tsp and rest all being
used interchangeably the system does not
care we do have a weighted matrix which
is if you have a did document that says
I talk rest didcom and tsp it will
negotiate in order of TSP first. If that
doesn't work, fall back to DIPCOM. If
DIDCOM doesn't work, fall back to rest.
And that's again based on the opinion
from a security and performance
perspective, we think they go in that
order. uh in terms of just modern
aspects of encryption. Um, one of the
important things with any messaging
system is well, how do I talk to you if
you are on a air gap network, if you're
behind that gateways, if you're moving
around? Um, the great thing about your
VTA, if you don't use REST, which we
would not recommend for a VTA, then you
can move your VTA anywhere in the world
and there's no URL that you have to keep
updating and repointing via DNS to where
it goes. You've got these messaging
relays or mediators that allow you to
abstract where you are. And this is what
allows you to punch holes through
firewalls, through NAT gateways.
It can obuscate where you exactly are.
There's some pretty clever things you
can do. Again, I come from a bit of an
interception background, so you can do
things like hide behind mediators in
different countries to create constant
timing attacks or even based on latency.
I don't know where you are. And you can
do some really fun routing such as
mediator to mediator to mediator. So for
example, if um Daryl and I want to send
messages to each other, but I might have
Jeff in the middle,
Daryl really never knows what my
mediator I'm using. Jeff will know what
mediator I'm using, and Jeff will pass
that to Daryl, but I won't know actually
what mediator might be between Jeff and
Daryl as you go through this. So this is
where you get a whole bunch of security
coming in. If you've ever built an async
messaging bus that has multihop routing
like this, uh read between the lines.
It's super complex, hard to get working.
I wouldn't say we've got it perfect yet,
but uh it's going really well. So, what
does it look like on the wire? Uh it's
pretty efficient. Um one of the things,
again, you'll see this in the demo. You
may be thinking, "Ah, problem with
anything decentralized, it's fat, heavy,
and slow."
You're not wrong. Um but what we've been
doing is driving this to an efficiency
where for example the authentication
flow we have is the fastest authent
authentication flow on the internet
right now. It's faster than anything
else. Anything open ID oorthth even
simple username password it's as fast or
faster. It's crazy what it does and it's
because of uh some of the things it's
doing. Uh basically at the inner is your
trust document. It is also signed. You
then wrap that in the messaging layer, a
sealed to the recipient. There's then
routing envelopes that go around it.
Again, we don't care whether it's limp
P2P, DIDCOM, TSP, and then you have a
transport agnostic, whether that goes
over a web socket, HTTPS, HTTP3, quick,
uh you can print it out on a piece of
paper for all I care, it doesn't matter.
And again, this is really important. And
you know, Adam, uh, our CTO, you're
saying is, you know, if you're going to
do it, do it two or more times because
it just makes you have an interface and
abstraction point for it. And so this is
some of that design thinking coming into
this. Um, what this means from an
implementation point of view, if you use
the trust task library, which is all
code gem, so you get that for free.
It also has the bindings which means you
can plug and play and move from DICOM to
TSP
without really any code changes
whatsoever. And this is something that
before we had this library was almost
impossible to do uh from people as you
go through. In terms of what this looks
like in reality and why we are big fans
of TSP, I was a big fan of Dipcom. I
love Dipcom. still has a soft spot for
in my heart. But the problem that
DcomCom has is as you start to route it,
if you do lazy routing,
you're losing some of your privacy. I
can see everyone in between Drummond and
I can see that Glenn and Drummond are
trying to send a message to each other.
So the way you would protect that is I
would nest the envelopes. I would say
I'm going to send a message to Drummond,
but I'm going to send it via Adam.
Adam's going to send it by Anna. And
every time you do that, the message
grows 1.6 to 1.8 times per hop. Or a,
you know, kind of 100 kilobyte message
quickly gets 20 to 40 megabytes in just
10 hops, which is not that many out
there.
So what TSP does is TSP
brings a lot of what DIDCOM does. Uh but
that 10 hops of 100 kilobytes only grows
to about 120 to 130 kilobytes which
again if you're dealing with mobile
devices you know I live in Southeast
Asia uh networks are not always the best
in developing countries people on cheap
devices you don't want to have uh very
heavy protocols or be sending around
megabytes of traffic as you go through
it. So this has been really really good
learning. When we started this, we
didn't know that we would be using TSP
until we ran straight into the DICCOM uh
size library. Yeah.
>> What about postquantum computing crypto
primitives?
>> Fully fully supported. So for
>> this will bloat all your uh
device coding there.
>> Not not by too much actually. Okay.
>> Not by too much. So if you look at like
MLDDSA 44, the keys get bigger, but the
actual message being transferred over
the glass, it's still the same size.
>> Okay, cool.
>> Yeah.
>> Uh the speed at cryp encrypting and
decrypting slows down the problem
because this will have a latency effect,
>> but it's not too bad. Um again, depends
which PQC you're choosing to use, but
yeah. Um all right,
trust tasks. So I'm not going to go
through this in detail but basically
everything is a URI 350 specs uh five
transport bindings. Basically what
happens is
um you have the ceremonies and you can
effectively build whatever you want out
of them. Everything in VTI that you'll
see is all running over a trust task of
some form. uh and the ceremonies that
you go through this you can also do some
fun things and I'll give you a demo of
this in a second is one of the problems
let's talk about DID management if I
have a web VHD ID it has pre-rotation
key setup for example which means you
can only legitimately rotate to the next
log entry if you have proof that you can
have ownership of the pre-rotation key
and you sign the next log entry with one
of those keys. But if I'm hosting that
DID on a did hosting service, that means
I'm going to give the keys to them if
they're going to be able to edit that
DID or make a change to it. So what
we've done is created uh delegated trust
task execution which allows you to
effectively
have sensitive data published onto a
third party but never share the keys or
the ability for that person to make
changes to your information.
This started off from the did management
from a UX uh aspect but interestingly
has really become powerful in things
like healthcare industry. You could
imagine being able to do things like
share a medical record but no one else
can edit it for example and if they do
want to it would be a delegation to a
doctor or a nurse to make changes to
your electronic medical records as you
go through it. Um it's really cool.
Let's have a look here. What else we
going I'm just going through this. we
get into demo time. Um there's a lot of
learnings that we've gone through this.
Uh there's a browser plugin. There's,
you know, we've one of the things we
wanted to test was could you have Chrome
talk natively didcom and TSP from a
plug-in without using any REST. Uh good
news is you can. Um, and so when you see
the browser plugin, it's all using
native messaging protocols uh from it,
which is really, really cool. Good luck
getting that through the Chrome store.
Having that debate with them right now
as you go through. Um,
one of the things we also did is we are
targeting the Linux kernel and therefore
by extension Linux foundation. Um, one
of the things we do is at Affinity, we
really think about scale a lot. happens
when you've got Adam and myself ex AWS
um tech talent. Uh and so one of the
things we modeled is what would
all of the Linux foundation look like?
You know, you got over 256 communities
made up of six big networks, 8,300
entities, 18,000 credentials. This is in
reality
what uh these things kind of look like
as you go through it. And so this is it
here live. You can go in and kind of see
what is happening. And you can actually
see the credentials here live as you go
through. So these are real DTG
credentials. This is a real graph made
up from a lot of these relationships at
scale. And what we realized when we did
this is just to model the Linux
foundation
the credentials here is about 600
megabytes of credential information. So
it's big. Um there's opportunity to
reduce that down. Uh you know number of
edges is extremely high. You can all do
types of fun things. I can send this
out. You can kind of have a look at it
uh if you want as you go through it. But
interestingly, even at 600 meg, creating
the graph from that and working with the
graph is super quick, super fast. Um, as
you go through it, it's just the signing
things. This is where PQC will by the
way. Um, having the much bigger
signatures will blow that out to a
couple of gigs as you go through it. Um,
if you are on the DTG working groups,
you'll see there's quite a lot of
tension between Drummond, myself, Jeff,
and others, Brendan, Alberto. The reason
why we're very very pedantic on keeping
the DTG credentials as small as
possible, as generic as possible, and
kind of trying to overload them a little
bit so that they can do as much as they
possibly can. It's to keep this size
down. And again, it's something you
don't understand until you build it at
scale and try to interact with it uh as
we go through it. I don't think any of
us thought
a Linux graph would be 600 meg in size.
If you start thinking about this going
out to, for example, all AI agents
joining a network,
there's going to be a lot more than
8,000 nodes in that network. Um, China
with a billion plus AI agents.
That's a damn big graph as we go
through. And so these are what we are
building and designing for uh kind of as
you go through it. Um, you can kind of
do routing, you can do everything here.
So what can you do today? Um you can
define one of three communities. So you
can define a public community. So this
would be the uh Linux kernel would be
the exemplar. Um you know everything you
see is able to be seen by everybody
else. I will note that while there is
kind of KYD know your developer
that doesn't mean that publicly I have
to be known as GL. So, I can still be
anonymous to people out of the
community. It's just part of my vetting.
I just had to show that I'm Glenn. I'm
an Australian citizen. I'm not from a um
sanctioned country. Uh I know people who
vouched for me, but I can be Donald Duck
within that community to others. Uh
there's no important that is a
governance policy decision at a
community level. The second use case is
what we call the house where nobody uses
names. to get into the house, you have
to be known,
you have to pass some checks. But once
you're inside the house, moving from
room to room, well, if you're in the
house, I know you've already been
vetted. It's okay. You don't need to do
anything else as you go through this.
And so one of the examples here that was
talked last week on the prem school I
think Drummond this came from one of
your meetings in uh New Zealand was what
about things like women's shelters for
example extremely high degree of privacy
but they also need to have proof of
government identity so they can get
assistance and the right you know kind
of health support mental health programs
etc. There's a lot of support material
just making sure that is being managed
effectively as well. So how do you do
these two things? I need to be known.
and I need to get access to the
government programs but I want to be
absolutely you know no one else knows
that I'm getting this assistance or help
as you go through. So that's that uh you
know kind of the pair-wise aspect. There
are you know onetoone relationships and
then there's a community
um aspect and the model here is actually
think about an enterprise company they
inside the company actually may be
public but it's private to outside but
even inside the company they may have
relationships with their ecosystem that
are private
depending on who the ecosystem player
is. So this is where you get a lot of
kind of mixing together of some aspects
of being public, some aspects of being
pairwise and you're using those in a
hybrid model as you go through it. Uh so
that exists today. U by the way you as
one person you can actually be a member
of three communities with three
different styles here and you can choose
whether you want to use your same
identity or whe you want to have three
different identities as you go through
this. Uh it's your choice. Second thing
is the join ceremony exists. So today
the way that works is you have openvtc
which is the developer tool. Uh I will
give you fair warning. It's the Linux
kernel team. They live in the terminal.
They love text braced user interfaces.
It is not beautiful. It's not sexy. Uh
that's what they want. That's what they
get. Uh you've got VTC which does have a
web interface and then you've got your
VTA as part of. So those three tools all
work together. Open VTC asks VTC for
what's the join manifest? Drummond, what
do you need for me to join your
community? That's the join manifest. I
then go and gather the material.
Drummond said, I want to know I'm an
adult. I uh am a member of LFDT, for
example. I then submit that back. It'll
present that back to Drummond's VTC. uh
where he then does a whole bunch of
verification and validation checks and
then he decides based on that material
whether he's going to accept me into
that community or not and let's say he
rejects me then I just I may not get
anything or I may get a rejection notice
or he's accepted me and then I get a
verifiable membership credential and an
endorsement credential saying what's my
role within that community. So it's
quite simple uh as you go through it.
And then there's the recognition. If I
want to be recognized outside of that in
a way again this is where the trust
registry query protocol comes in where a
community can start saying hey Adam do
you recognize me uh because I'm saying
I'm coming from Drummond's community and
Adam might say I have trust because
Drummond's community is actually part of
Grace's greater community of communities
as part of diff for example. So you can
start building up uh the hierarchies as
you go through this. So that exists
there today. Um
the other one I'm not going to show this
today. Uh but this is really what we're
building for the Linux kernel is if you
know you're developer then apply that to
the world of git. So when you do a git
commit which is committing your changes
to the code best practice is you should
sign that git commit and if I can sign
it then it's proof that it was uh
developed by glam submitted by glam
committed by glenn and then if I have my
you know use GitHub here as an example
if I have GitHub actions that get run on
every single time I do a commit or when
I do a pull request the GitHub action
can now talk to the open-source
community and say, "Hey, is Glenn even
allowed to do a PR? Can Glenn merge his
own PRs?" Uh, does Glenn need to get
Mitch to approve that? And once Mitch
has approved three or eight or 10 of
these above Glenn, we're going to
elevate him so that he doesn't have to
go through a uh vouch from another
maintainer as you go through it. So, all
of this is like really quite fun. Some
of our own team are using this already
inside Affinity uh for code development
on the platform side as you go through.
It's really really cool. What's nice is
we hacked git to get this to work. So
for the geeks in the room uh git only
allows uh GPG signing or SSH signing.
But in an SSH sign, you can put what the
key identifier is. and it does take a
div identifier and SSH supports ED25519.
So we've hijacked the back of SSH and
interestingly when you do that it shows
up with the green verified tick on
GitHub.
>> Did you check it in as G10? [laughter]
>> Did you check that in with G10?
>> No, I checked that in as GG. Uh no, not
the ZX hack. Uh for those that not know
what Daryl's inside joke is there. Um
the other thing you can do is with your
trust agent
you have this concept of linking
multiple devices to your VTA. So I can
have my laptop, my phone, my tablet,
desktop, whatever I want and I can
choose depending on the trust context
what gets shared across these things.
One of the most powerful uses of this is
actually when you start using it for
agent memory. So I can store something
and say I don't know Drummond's favorite
food is beer and uh is that a food
group? I think it is. Um and then when I
ask that on any of my devices, it's
going to come back through it. So those
of you in the AI world, if you know
things like ME zero or Enthropic has
just been adding this themselves into
their own tools, this is a way of having
agent memory that is agnostic to any of
the AI tooling you have and you can plug
into it via MCP. There's also an MCP
interface for your VTA. Be careful with
it. Um, but you can ask your agent to
manage your VTA.
So depending what I got this
credentiing, do I want to do something?
So you can start doing if this then that
type triggering as you go through it.
Uh, there's plugins for this. There's an
MCP server agent. There's a claude code
plugin directly that you can use. Super
cool. Uh again, just be careful if you
give it right access. Um default is just
have it have read only as you go through
it. Again, you can have your AI agent
plug into the approval policies so that
depending on what it does, it will ping
you and say, "Hey, your agent's trying
to access something. Do you give
permission to it?" Yes or no? All right,
enough talking.
Uh I'm going to apologize in advance.
Jeff, is your computer working?
>> You're back online. So Jeff's having a
lot of things. So maybe I'll just give
you
a quick little demo and then Jeff's got
a hosted version of this. Uh let's see.
Everyone pray to the demo gods. Uh and
see what happens as we go through this.
So
um so first thing I'll show you is this
is open VTC. So I'm going to tell you
this is live. Um, nothing here is
pre-recorded.
It's probably going to crash at some
point
to prove that it's real. So, this is a
blank uh profile. It's basically asking
me I can recover from backup. We're
going to do a new profile setup. And so,
the first thing it's going to ask me is,
can you give me your VTA's DID? And so
over here we have the personal network
manager tool which I can already see
there's my uh web VHD ID here for this.
Look at that. There's an error down
there as we go through this. So all I
need to connect is I'm basically using
my public infrastructure. So I'm telling
my client here who doesn't know about my
VTA here's what it can do. It's going to
resolve that DID and get the service
endpoints and basically negotiate how to
talk to it. Now what it's saying to me
is okay
you need to
because this is a new setup I want you
to create a trust context we're going to
call it open VTC and can you give access
to this administration DID that we just
created itself which is just an
ephemeral key and this is going to
expire in 1 hour so sure no problem
we're going to run that over Yeah.
Okay. So, this is the P&M. So, the PNM
is just the interface to your VTA.
Remember the VTA is not running on my my
my machine. My VTA is actually running
in Ireland at the moment. Um, so it's
created the context. You can see, you
know, there's some tech info in terms of
the way the context and keys work. They
are derable, which means I don't have to
back everything up in the VTA on every
single transaction. I can kind of derive
it after the fact as we go through this.
So, what I've done now is I've
effectively OpenVTC has figured out how
to talk to the VTA. It has created a
ephemeral key on the client side and it
said, can you create an ACL entry on the
VTA so I can connect to it? So we say
yes, you can. And now it's negotiating
access and it's just rolled the keys. So
you can see here it just rolled the
admin key. It went from the ephemeral
key to a DID key that the VTA actually
just sent back to itself. Uh as this
went through this, it's authenticated
via TSP, so it could have fold back to
didcom or rest. Uh as you go through
this, um
everything's good. Uh now it just goes
through the rest of again because this
is the Linux kernel. Um particularly you
know people like Lenus and GKH they will
have some mandates on using hardware
tokens but we're just going to skip that
today. We're not going to require an
unlock code because we live on the edge.
Yes I understand that's dangerous. Uh
that's it. I'm in. I'm connected and now
I can start interacting with things. So
I can go down to my VTA service. We can
see that uh I'm connected. I don't have
any persona DIDIDs. I have no invitation
credentials. I don't have anything. I've
got all my logs. So, what we're going to
do is we're going to join a community
now. And so, similar again, the join
flow is it's going to ask me for
a
um
so this is what a VTC looks like. So,
this is variable trust community and
here is my community did. So I want to
join this community. I put that in. And
so what it's doing here is I've just
created from the VTA myself. I've just
created a brand new DID for this
persona. So I'm not joining as my VTA.
I have then asked the VTC what do you
need to join? I don't have a verifiable
invitation credential. So effectively it
has uh joined a queue and I'll show you
this in a second. And now what it is is
I'm in a wait state. I've basically said
here's my persona did. It's called sorry
dessert. It makes up names on the fly.
Uh and it's waiting for a response. So
we can actually see some of this pretty
fun. So if we go over here, this is a
DID hosting platform.
I'll come back to this and we can should
be able to see sorry dessert is here. So
this is the did that was just updated.
We can see there's no traffic to it.
Here it is. It's a web VH. I didn't have
to worry about setting up keys. I didn't
set up pre-rotation. We can see here,
you know, it's a portable DID. Um, it
does have the key management uh
pre-rotation on. It's not deactivated.
It doesn't have any watches or
witnesses. Great. This is working
perfectly. If I come over to the VTC
and log into this, I can see here
everything is looking good. My trust
registries will arrive. This is the
trust ceremony. So I need to basically
work through this for a join flow. And
what's happened is I've effectively hit
the problem where I don't have a valid
invitation. I do not have a VIC from the
VTC. So what's happened is I've gone
into a moderator queue. So this is an
example where the policy starts to work.
So if I go over here to join requests
here, I can see sorry dessert is in
pending and I haven't presented any
credentials because this ceremony just
for simplicity is not asking for
anything. So if I go let's just make
sure this is going to work. I'm going to
click on approve and I've approved that
and over here we're active.
So I didn't have to there's been no
transfer of secrets, passwords, anything
whatsoever as I go through this. You can
see here that I have my membership
credential and I also have a RO
credential and I can see these by going
over here and I go to membership and you
can see here here is the actual
decentralized trust graph credential.
Uh what is this one? This is membership
and it's got 29 days left and so it will
auto renew and revoke things as you go
through this. So again did I have to
know anything about the VCs, the DTGS? I
just joined a decentralized trust graph
and didn't even know it. And I can prove
that because here is the trust graph uh
starting to come in as you go through
this. So there is sorry dessert and if
we click on that we can see that it is a
full connection. Uh it's a VMC pair and
that sorry dessert is a member of data.
Forget the UX for a second. Uh some of
this stuff is coming hot off the brush.
>> That trust wrap. So for this one, this
would be the VTC administrators own.
So this is a only within the community
at this point.
>> And then if it's a network of networks,
>> then the community would choose to
export parts of that to outside of
themselves via the trust registry.
>> Exporter, expose, sorry, expose.
>> Does anybody need to see the trust
graph?
>> Because Adam might be running
open-source community. I might be
running an open source community. And I
want to recognize that if you've been an
active member in Adam's community and he
says you are a good developer, you get
instant access to my community. So to do
that, I want to see his trust grow.
>> Why would I need the graph? I just need
the verifiable credential from the
person who says I belong.
>> That also allows me to start seeing the
graph. So I don't have to see the whole
graph. Just seeing the credential allows
me to start seeing part of the graph.
>> Why would you let me see part of the
graph? All I need. It's your choice if
you want to. Some communities will want
to expose the graph. You have the
ability to either expose all of the
graph, parts of the graph, or none of
the graph.
>> When I'm an individual showing my
credential, how do I know what I'm
exposing about my friends?
>> Because the VTC part of the policy of
what it does should be describing what
what is it doing with your information
as you go through this? I
>> just really don't understand why I would
want to expose part of my graph to
another community. I don't understand
the purpose of that.
>> Like if I say this is a trusted member,
they're a trusted member. Why would I
need to expose any of my graph? I don't
understand.
>> But that is that is exposing part of
your graph. That is a by definition of
DTG credential. It's just you're
exposing one node of your graph.
>> One node fine, but I'm not exposing.
>> But that's a graph. A single node is
still a graph. So this is a semantics.
You don't have to expose the entire
graph in its entirety. But if we start
to share 10 members from one community
to another, you've now got 10 nodes.
That is the side of a graph. And they
may start to create VRC's amongst
themselves. Now you've got a new graph
starting to form independently across
two communities.
>> Like like you're calling something a
graph when I'm kind of like, okay, it's
a list of members of a community.
>> Not a list. It's a it's a graph. It says
knows link to notes.
>> Yeah, that's why it works.
>> A list is a graph.
>> But why do I have to know who knows who?
>> You you don't. It's if you want to. That
say I would just say
>> I'm just saying like if I knew everybody
who was in this room.
>> Yeah.
>> I still didn't don't need to know who
issued who a relationship. Like I might
have more of a direct relationship with
five of you, but not a direct
relationship with any of you. But I'm
still a member of the group. Why would
it matter who I was related to? in his
only way was really relevant for giving
the access.
>> So, so it's not endorsed by that guy.
So, you need to say, "Well, I'm endorsed
by that guy. So, that's that's why you
should let me in."
>> Yeah. It's not shared proactively unless
the community chooses for transparency.
They are going to show all relationships
within their community.
>> So, the assumption is that these
vouchers are endorsement that you belong
to a group.
>> Again, it depends on what the community
wants to do. So for Linux kernel,
>> it is very public that if you're a
member of the Linux kernel, that is
something they publicly expose today via
the web of trust with PGP today.
>> And and that's and the way that they do
it is is that if enough members say
you're a member, then you're a member.
>> Yeah. It's it's the their own
>> that and you can see the link which
members brought in other members, how
far away from Linus they are. It's all
it's all graphed out. I can totally
understand why within the network you
need that information like who vouched
for this bro, right? Like that totally
is clear to me, but it's totally unclear
to me why outside of like if I know like
why outside anybody would care who vouch
for that bro.
>> Just to make it clear
that's under your control and the
community's control
>> always. There's no defaults for setting
in the trust graph. So
>> I'll turn it on.
>> Yeah. Yeah. Don't turn it off. So
whatever the community says this is what
we want to expose or not, they control
that.
>> And if there's only three people who are
authorized to give membership, let's say
there's three people and they have to
give membership. The trust graph will
always show just links to them and not
links to each other among like the
trust.
>> Are they giving membership in the
community?
>> No, membership comes from these three.
There's a membership community. The
member there's a membership board of
three people. I'm just calling it that.
Those three people have to vote you in
and out and that's it. The community
doesn't have to vouch for you. It's
those three people.
>> Yeah. So in that
>> membership board allows you in in that
graph. Would it just be like a downward
graph?
>> Yes. So well so different. So again some
of this to be fair Grace we're still
figuring out. So these are good
questions. But in your example there,
the three authorized members, they
effectively be giving some form of a
vouching credential saying I I check
Jeff and Jeff's real. And then when the
three of the approved um administrators
do that, they actually send that back to
the VTC. And the VTC says when I collect
three of those from people who match the
policy, the VTC is the one that is
creating the membership credential, not
the three maintainers. And so those
three maintainer credentials, again, you
could choose to never expose to anyone.
That's just internal to the VTC
governance policy. All the graph would
show is that the VTC has decided that it
is a member of that community, but you
may never know who the three were that
actually vouched for them.
>> I see. So just like and the network
draft would just look like a everybody
is coming from this command.
>> Correct. So this and this is the
difference between a vouch or an
approval mechanism or like an endor. So
an endorsement credential is not an edge
or a note for example.
>> I understand
>> it's not it's not an edge or a note.
It's a it's like
>> like I can endorse you. It doesn't mean
much because I don't know you very well
but I could endorse you.
>> That's right.
>> Right. So any form of organizational
structure like a a corporation that has
you know a hierarchical corporation and
just design it that way and and then it
would look the graph would end up
looking like a hierarchical org chart,
>> right? Um and yeah, whatever membership
rules they want to do that the the the
whole idea of the pure vouching is
something that's that's the Linux
Foundation PGP web trust rules.
>> That's clear to me. I understand that.
>> Yeah. And that's inferred like if I know
that to be a member you have to be
approved by the committee. If I show you
a membership card, I know the committee
approved you. That's right. So I'm not
that network doesn't expose something I
don't already know. I know you got
approved by the committee if you're
holding a membership card. So those
relationships are already built in.
>> Correct. Correct. And this is where one
of the first use cases of ZKP is exactly
for that is the vouching aspect. So that
even at the admin level, you may not
know who actually vouched for them.
>> Right. It might just show the committee
and the committee might be voted in
every year might be different if I'm an
old member, new member.
>> Yeah. Clear.
>> So just the good questions discussion.
The thing I'd say is I'm looking at this
from a platform perspective. The
platform doesn't restrict what you can
or can't do.
>> I understand.
>> Uh how you set up your BTC is very much,
you know, how you set it up Grace is
probably radically different to how
Lenus wants to run his community. Uh
sure. Same tool though. um as you go
through if I could add a couple point I
think what you're sharing is that you
have a perspective within a graph
>> rather than you're sharing the whole
graph every time because this also gets
into the PPC thing like I sit within
this graph and I have a perspective
because I have someone has been invited
which is why it's often one to one and
that's the only thing that gets shared
but if you had multiple perspectives
within this room then you would actually
see us all starting to connect and your
view of me within the graph will grow if
that makes sense. So it's kind of like
yeah you can look at a map but then
behind the map there's a territory and
you can't see the territory but you can
see the map. And then the second point I
wanted to make is that I don't actually
think and I've made this point a couple
times. I don't think we're always going
to be computing the whole graph all the
time. I think we should stay away from
that as much as possible. I think it's
we have our own version of the graph.
You compute your own version of the
graph. That's your perspective and you
can choose what
>> you would like to share and that's
[clears throat] going to save us on the
again the keys and signatures as we go.
>> Yeah. Well, in some ways, like you could
say something. I mean, it's kind of a
silly way to say it, but in some ways,
even though I know all of you, the only
node that vouched for me was Drummond
because he invited me to this. And so,
even though I can see you, there aren't
and there's nothing on the network graph
about our connection to each other.
They're only
>> as it relates to this room, I only have
one voucher in this room.
>> And that's why when you think about the
graph, there's three dimensions to it.
There's the node, there's the edge, and
then there's annotations on both the
edges and the nodes. So things like a
vouch, an endorsement,
um, invitation credential, they are
annotations that allow you to have extra
information that is tied to either the
edge or the node. And to Mitch's point,
that is often very much from your
perspective that you are looking at the
graph from, not from a holistic like the
whole graph probably wouldn't have all
of that information in it. I don't see
why there's a reason why you would want
to unless you're an extreme public.
>> Yeah. I mean, you know, sometimes people
have fun giving each other pull offs and
stuff, but other than that, we generally
don't. We're taking selfies together,
but generally most of the people I know,
I don't have a selfie with them. Yeah,
but this is just true to this again.
I'll send this link around, but this is
where you start getting into
>> you get into different graph
[clears throat] theory and you know it's
very hard to come up with a system
a single system and framework that has
to deal with these radically different
extremes. You've got one extreme that is
everything should be known and the other
extreme nothing should be known. And
we're trying to basically can we have
one implementation that deals with both
of those plus the in between anything in
between the two extremes.
>> Yeah, totally makes sense.
>> Yeah. Uh all right. So we can do
something else. Uh so we're going to
create a new persona. So remember I
joined this DID this VTC. I'm known as
sorry dessert. Um so now we can do
something. I'm going to be known as
we're going to join as Drummond. Um
>> so I've just created a new persona DID.
So this is really as kind of as simple
as it gets and it's an orphan Drummond.
You have no community.
>> You have no community.
>> So
this turned into a bullying session very
quickly.
>> Uh so now what we can do is I can do
something interesting though because
Drummond and I met and we're just going
to do a little hand wavy thing here. And
what am I invitations? Um, so Drummond
and I met and Drummond said, "I want to
join your community." And I said,
"That's great, Drummond. What's your
did?" And he's created this uh he's
going to be soon virtual. Oh, that's
like looking around the corner. You're
going to be soon AI. Uh, soon virtual.
So, what I'm going to do is I'm going to
create a VIC uh verifiable invitation
credential to him. And, you know, I can
set what it's going to be. I can say
what role uh here is. So, I'll just say
you're a member. And I've now created an
invitation for Drummond. And you know,
if we had this, you could do a QR
snapshot of it. But we're going to
copy and paste this. And so Drummer now,
and I send that, I could email that
invitation credential back to Drummond.
I'm Drummond over here. So I can go here
and I can say, I want to join another
community. I'm actually going to join
the same community, but with a different
persona. And so I'm going to join. So I
could see here I could well I can't join
as sorry dessert because I've already
there can't have it more once but I'm
going to join as Drummond. And uh yes it
links me across everything. Uh I also
have uh an invitation credential that's
sitting in my clipboard. So I'm just
going to say uh pasted that in. And so
you can see the invitation just got
pasted in. Now, what's going to happen
here is when we join, fingers crossed,
when we join this VTC, because Drummond
has a valid invitation, he's going to
not go into the pending queue. He's
going to go straight into accept uh as
we go through. So, we can kind of just
double check all this uh members been
logged out. Uh
there is no member here. There's kind of
sorry and bamboo. uh you're going to be
soon virtual. There's no join request
for you.
We have the invitation credential here.
Um okay. So if we click over here, this
is now submitting. It's presented the
aspect
and there he is active in the BTC. So
it's literally as simple as that.
>> Acceptance
>> as you go through that. So Grant, you
now have friends with him.
>> You're friends with yourself. uh uh as
you go through and again the VTC is
done. All right. Some other fun things
you can do with this. So you may have
noticed when I was logging in, did
anyone notice how I'm logging in
uh
>> I using a self-issued open ID provider
that is coming from my VTA. So I have a
little browser plugin running over here.
I can have multiple VTAs.
So, this is using the GDC uh demo one,
but I could use my US-based one. And I
can do things like load what are the
websites that I'm allowed to join as I
go through this. [clears throat] And so,
you know, if I sign in with a pass key,
we all know what that experience looks
like. I do this, it thinks about it, it
lets me in.
If I just do this, I'm in. And that's
logging in by the VTA. There is no my
login credentials for my VTA are not in
my browser and this is talking TSP and
DIDCOM from the browser plugin directly
to the relying party with the VTA's
approx. So we're here in Geneva. This is
running in Ireland. Uh we did one
earlier with Jeff and he was his VTA in
Frankfurt. It's no difference in terms
of speed uh as you go through this. So
that's fun. Um
>> there's no cookie.
>> What? Sorry, no cookie.
>> Nope. Nope. It's like really quite
clever. Uh so then you can do some fun
things like
>> if we go to our plugin, you can see here
it's all designed to help educate
people. Um but I can do things like show
me my network. So I can see here's my
trust agent. It's connected to this
messaging relay. This is my wallet, my
browser plugin. I have a separate
approval identity that's actually
running that'll do step up approvers.
And then I have these authorization
authentication profiles that allows me
to sign into these different websites as
I go through this.
>> So do you have any other authentication
means for the wallet itself?
>> Yeah, you can uh Yep.
>> But because if I mean if you just click
obviously you're pre-authenticated to
the wallet and and presenting whatever
keys you need but uh you obviously want
to have some ring fencing of the wallet
itself, right?
>> Yeah. So the wallet if you if I do this.
>> So first of all everything is encrypted
on I can't the wallet's blocked now. So
uh I have to unlock it. So
>> okay so use the the the biometrics on
the device for
>> you question uh do you have any
provisions for having you mentioned
hardware keys for for key stores. So you
could have HSM and other
>> hardware criteria certified stuff. Okay.
Yeah, we just don't do it because it's
just doing it all the time. But yes, um
so you can see here this kind of
describes to people, you know, how it's
working,
>> approvals work, uh testing this stuff is
really hard. So we have a lot of kind of
like livveness checks,
etc. But you can do something really
cool. So
this is the DIDs uh that have been
created. We can see Drummond's soon
virtual. So remember this DID is sitting
inside the VTA. This is a third party
did hosting service that is not
connected to my VTA as in it doesn't
have any of the keys. So we're going to
edit Drummond's document and uh
>> frozen berries.
>> You want to make frozen berries?
>> Yeah. Sorry.
when we were in health sync even
translated a menu and it said
>> frozen nose bed please.
So there's some fun things here. Again,
if you're working with WebVH, and again,
it's a web VH is very powerful, but it's
difficult sometimes to think about I've
got to edit the DID and then I've got to
create new signature sign. I've got to
create new pre-approved keys. There's a
lot happening around it. You can see
we're on version one, but I can just say
publish with my agent.
Uh it's not going to work. This is not
in the right space. this one.
We'll do this one.
So, I just didn't give access to it,
frozen berries,
and there you go. The VTA just updated
it and it's now on version three and
frozen berries in it. It's as simple as
that. Uh, all the keys have been
updated, changed. You can do whatever
you want. Um, we can do things such as
there's an agent name here. So, those of
you who haven't seen an agent name
before, these are really cool. You can
go into a browser and straight away
resolve to my DID as I go through this.
And that should also mean that if I go
back to agent open BTC and go to my,
you'll notice here the VTA is known by
its agent name, not by DoD. So this is
some of the UX stuff that's starting to
come through as you go through. So you
can resolve a DID one of two ways. You
can either resolve it by its full name
there or
as simple as that as you go through it.
And they both reserve uh they're both
protected uh from each other because the
also known as goes through this. So
there's a lot of kind of powerful oops
uh capability that goes into this as you
go through it. I'll stop there because
that's been a lot.
But yeah, um again, first target is
Linux kernel. So a lot of this is very
skewed towards their use case. I'm kind
of skipping over it. There's a whole
bunch of things um we skipped uh as we
go through that
credential.
>> Uh so you did exchange credential. You
just didn't see it. The thing reason I'm
not going to show you a VRC is because
then I've got to set up multiple
relationships and we can do it. So Jeff,
I don't know if you want to show hosting
capability if it's working.
>> It's Yeah. Well, my computer uh yes,
we'll get the just for protocol. Are we
having coffee break at some point?
Because
sorry the idea is once you're done with
the demo, we we could do it now. Do you
want to do it now before?
>> Uh, I mean, let's let me just give a
quick just to show what's built really
fast. Um,
>> the coffee break, there's a coffee place
just like a block.
>> So, we're [clears throat] going to just
migrate over there for whoever want.
>> Where's the sauna from last year?
>> There's a gym at the end of the hallway.
[laughter]
>> You really want to sweat?
>> It's pretty hot out there. So, I'm glad
this time we have a more temperate.
>> I'll I'll make this really quick.
>> Okay.
>> Just I think everybody wants a break,
but it's good that you can wrap with
this.
>> So, as Glenn's been building all this
stuff, the question that came to my mind
and Vincent's mind who's been working on
this and doing the bulk of the work that
you're going to see here, the question's
been, you know, how do we make this
easier? Because setting up a VTA, you
had to stand up a server and then you
had to get a lot of ducks in a row to do
it. and we learned to do that.
So what he's done is he's gone uh
Vincent and has built a um Kubernetes
deployment of the VTA uh stack. So
there's a couple bits to it. We have it
all deploying on top of Kubernetes. So
for instance, uh we've been using Hner
as our main um as our main source of uh
is where we're storing stuff. So we've
got different stacks here. So we have a
staging stack. Notice there's three of
them. So it's a high availability
cluster. We have what we call our
production stack. And then we have a
rancher which is the Kubernetes
orchestration also has high
availability. So and you'll notice
they're in different places. We have
some stuff in Nuremberg. We put the
staging in Helsinki. So if we needed to
do a demo and things crashed in Germany,
we could hopefully be running in
Helsinki at least. Um
what we've done here, let me just show
you this real. Yeah. So all this is
controlled through rancher which is a
basically it's by soux it's a way that
works quite easily
we look here what we've got I'll show
you the production one um
I need to sign
yeah I don't have that one Yeah.
Oh yeah.
Sorry about this.
Okay. Now
it's this guy. What we have is it. So we
some basic statistics about what we're
running. There's a couple admin
accounts. Remember what she's doing
here. Not any users. you've just been
playing around with that Vincent and you
made mainly sessions. So, we've got what
we call the platform stack. So, this is
the full VTI stack that Glenn has been
demoing. So, you've got the mediator,
you've got the VTA, you've got the DID
host, and finally, you've got the VTC.
So, we can stand that up. You can
actually drill down into there, see all
the DIDs, you can make changes to it.
You can add an administrator to the VTA
for it. Got all the private keys there
and anything that you would need. Um,
and then each user goes and sets up
what's their own GTA VTA. So like I've
set up one here, which you know then uh
that allows you to do other things. I've
connected also for instance browser
plugin and got that working. Been
playing around with that today. Uh
that's all being driven through the VTA.
So what will happen uh is uh in in the
stack itself when a regular user goes in
like here I'll go sign in my regular
user. Uh, creating a VTA. You basically
go here. You say you want to create a
VTA. You give it a name. I'll just see
GT 2 because I've already got one called
GT. You select the image, the latest.
We'll be using the latest image from
this morning. And then you go ahead and
create session.
What this does now in the background is
it's basically spinning up a Kubernetes
pod that's creating the VTA. It does a
few things. And then within a few
seconds you basically get a DID key that
you link to the VTA to the PNM that
you're running locally on your computer.
And then so you'll see I'll just show
you that. So it pops up. So here it
gives you a gives you the like that. So
what I would basically do is go into my
terminal um and I would see PM setup.
Let me call this GT2 since that's where
I named it. I'll paste the DID there.
It gives me this DID key right here,
which is basically the master key that
I'm using on my local machine on my PNM
to talk to the BTA and manipulate it, do
everything I need to do. So, if I get
back here, paste that key in,
provision the agent, and in a few
seconds that'll be done. Now, at that
point, I've got a fully functioning VTA
up and running. I can then you do like
Glenn was doing run open VTC start uh
creating bids, start joining
communities, everything like that.
That's it in a nutshell just to show
some of the other stuff here. So like as
you can see the VTA farm it's we we're
using firstperson.dev is the domain for
it right now. So we've got hosting here.
I'm going to do the the fancy scop
login. Boom. I'm in. And so we've got
that all stood up. We've got the DTC
community as well. Same thing also under
firstp person.dev dev. It's all there
numbers. Well, me I've been speaking
this this morning, the dashboard,
everything that Glenn was showing you.
This is all running on Kubernetes. Now,
uh to set this up, we made a couple
opinions. We thought we're going to use
uh virtual private servers. We chose
Hatsner as the provider and we're using
Cloudflare for DNS. Those are the only
sort of opinionated things we've done.
uh we're using uh Terraform or Open
Tofu, the open source fork of it to
orchestrate the building of all these
Kubernetes servers that you see that are
running the cluster. Um thing that's
nice about Open Tofu, it's just it's all
declarative. You're not in there at the
command line doing it. You're just
telling it what to do. You plug in a
couple API keys uh to build this whole
thing that you're seeing here. takes I
don't know Vincent if you if you're
still there what's what's your record
like 30 minutes what how long does it
take to
>> 30 minutes
>> the whole process yeah take like 30
minutes is simple enough
>> a lot of that's just waiting for the
computers to do their thing waiting for
the cluster to get to a stable state
before it adds the next node in actual
stuff that you're doing at the keyboard
probably less than five minutes to get
it all up and running
>> so that's what we've done with that um
you know we're eventually going to make
the code public open source once we've
made some more improvements to it and
whatnot. But uh yeah, that's our little
side project to this whole endeavor, at
least for the last couple months.
>> Does the hosted VTA have a TE?
>> Not yet.
>> Is that on the road map?
>> It could be. Yeah, could be.
>> Yeah. Yeah. The trusted execution
environment is definitely something
we're interested in.
Yeah,
we're we're going for the low hanging
fruit first. So at least the low hanging
fruit.
>> That's awesome.
>> The the cost of the cluster was roughly.
>> Yeah, that that cluster is a little bit
beefier. I I mean you can build a
cluster that's Vincent's in the process
of doing some load testing right now,
but you can have a cluster high
availability cluster running for about
30 $35 US per month. Yeah. And that
could comfortably handle couple hundred
BTAS.
>> Couple hundred.
>> Yeah, probably. Yeah. Okay.
>> We're gonna load test it and see, you
know, is that real reasonable? But as
far as memory constraints of the cluster
itself, 150, 200, something like that,
>> right?
>> So you're talking 30 cents per VTA per
month.
>> Yeah.
Just so again that we didn't talk about
it, but the efficiency of the VTA and
the media is very high. It's very very
very high.
>> So if I was running a sovereign node, I
could run this VCA 10,000 times.
>> One one thought that I've got is is
setting up uh is this a trust task in of
itself?
>> Could be.
>> That's actually that's a good one.
Yeah.
>> Right. Like if it's half an hour of
runtime, that's a lot of attention a
person is putting on a computer. It's
pretty high like personhood veracity.
>> So that's 30 minutes to set up an entire
cluster for the whole thing on its own.
If you want like a VTA with BTC, like
say you want just create a new
community, Mitch's community, that's
>> how long
minutes
>> or VTA plus BTC.
>> Yeah, probably. Yeah, the question is
about the mediator and what you're going
to use for that. That's why we just put
it all together.
>> But uh actually, I should the 30 minutes
includes setting up the
>> the head.
>> Yeah. Well, the control plane and
everything like that. If you if we were
to spin up another instance of uh this
stack now, it would probably be like
five 10 minutes.
>> Okay. [clears throat]
>> Yeah,
>> that's so pretty.
>> Yeah, it's pretty good. Yeah,
>> very cool.
It's all real. It's all real and it's an
amazing amount of information and I can
tell we folks need some coffee.
So, um first thanks. That was amazing
amount of stuff. These guys have been
cranking on this for, you know, months
now. Um, and uh, it's good. By the way,
Andy finally um, signed off, you know,
in middle of the night for anybody said,
told me wants to copy your document and
he said there's a bunch of people down
there that they saw this, they would be
okay.
>> Happy send it to everyone.
>> Yeah.
>> Yeah, please.
>> Excellent. Um, all right. So, for the
folks online, we're going to take um our
our coffee break now, which means we're
gonna some of us going to walk over to a
nearby coffee shop and we're not doing a
inerson coffee service going on
something better than that. So, uh we'll
be back um likely, you know, let's give
ourselves 30 minutes um and then we'll
come back and we'll talk about state of
the uh uh first person project and go to
market. will also talk about um proper
GDC. So that will be the final portion.
We're we're we're only here through
fine. So
>> um let's let's take a half an hour for
coffee. I'm going to stop the recording
now. We'll have a second recording for
the
>> I'm guessing the reason we didn't really
do a ceremony is because only three of
us have Phoenix.
>> Uh no, no, you did do a ceremony. You
just didn't see it. So the ceremony
happened when you joined the community.
It just happened. It's automatically
applied from the policy. That's the
beauty of it. There's no need to be
involved on that one. So when I created
the VIC for Drummond, that was the
ceremony going through the ceremony.
>> I can do it again.
>> You mean a big You mean everyone joining
the VTC?
>> Vouching for each other.
>> Uh
>> I mean Jed vouched for me. I think we
have some
>> hoping to get like I only have two VCs.
>> Yeah, we didn't want to talk about why
we [laughter]
>> I was so excited when I got my first
bid. Like you just have to understand.
[laughter]
>> What you got a What laptop do you have,
Grace? Is it an Apple?
>> No, Linux.
>> I have an Auntu.
>> Abuntu. You've got a
>> I've got a I've got in a bunch of
>> you how to turn off the recording.
>> Problem is right now you got to compile
open BTC and it
>> nice work.
>> Yeah,
>> you should join the open BTC tool chat.
Speaking of waking up to 120 messages,
>> coffee.
>> I'll leave my keyboard.
Yeah.
>> I looked it up.
I brought so many
walk together. If you don't
try again
yesterday
by your
Well, I'm a cat person, but I can
say that.
>> Yeah, I'm only
[clears throat]
>> um
sorry.
enjoy.
>> Uh, I I got messed up getting here. I
didn't have I lost a lot of time, so I'm
probably just going to catch up on
stuff.
[clears throat]
coffee drinker. Uh,
>> I'm probably adequately caffeinated to
sleep tonight. Yeah.
>> Yes, I understand.
>> Yeah.
>> Who's Scott?
>> Scott, nice to meet you.
>> Cool. Scott Jones.
>> Stephanie.
>> Cool. I'm trying to see if I remember
you from from a Zoom call.
>> Probably not. This is a very new space
for me.
>> Cool. relatively new for me, too. Kind
of engaged in these communities starting
a year ago.
>> Oh, cool. Um, I've been working in the
space probably like closer to three
years.
>> Cool.
>> Uh, but like this was very that was very
technical for me. I know you came in a
little late. Um, and I understand
for the most part, you know, but
there's, you know, the technical sense,
there's a lot of terms and things being
thrown out. And
>> and what is your what is your specialty?
What are you doing?
>> I guess I'm for I see myself as a human
rights practitioner. Uh, I work for a
law adjacent
uh nonprofit. It's a coalition. It's a
>> say law adjacent nonprofit. Yeah,
because it's like a technical it's like
law Jason
>> it's more legal related. Um
how can I explain it in simple terms? Um
I I'm part of the Gleonet Alliance uh
founded by Richard Wit who is the ex
Google attorney. Um and what we want to
do is well that's all great what was
just being talked about then from the
technical sense. Uh but we really
believe like cool that's awesome but
there's no legal duty for that business
or that entity or the company or the
tech stack
and protection against like the users or
what we call them agents then where's
the recourse where you know like her
question was like okay why do I have to
do this like why I don't know if you
were here but she kind of had this
question she said like why do I have to
expose my graph
to like somebody else
like why she kept like you know like
then they kind of kept insisting you
know well you don't have to it's like
the community leads how they want to
expose that you can you yourself can say
you don't need to expose it if you don't
want to um and as she's talking about
that I'm thinking well the work that
we're trying to do is build up something
that we call an fiduciary so in the
sense of a business or a digital product
or like a service, anything whether that
from like a civic standpoint, a
government standpoint, a nonprofit
standpoint, like any type of realm in
the digital space that has this sort of
ownership and power over others in the
sense like users, not even those users.
um they can take on this digital
intermediary
fiduciary like uh role so that they are
protecting
um the people that they're working with
and that in turn would
uh continue to like bring more authentic
relationship between consumer and
business so that there's more trust
eventually. Uh so but it goes back to to
law. So we're trying to push for this,
you know, all this is founded on common
law. Like when we think about
professions where there's high trust
like a doctor, you wouldn't trust some
person with a scalpel to take something
out of your brain. to trust someone that
has a certificate or a law like school,
you know, the professional associations
that like can make sure they can take
away this, you know, scalpel from the
doctor. They're doing terrible things
and they're not qualified for that,
right? Um, well, why isn't that
something that's happening on our
digital services realm? Um, and so of
course it it gets highly complex because
there's everything wild now. Like it's
out there and um we're really standing
in the space of like nobody's talking
about us like a regular human like me.
Who's empowering me every day?
God
>> in the lane center.
That that was my little pitch, but I
probably botched it.
>> I'm uh I'm
coming from a different angle, but
trying to solve a similar problem. I
work on privacy preserving biometrics.
>> Privacy preserving biometrics.
>> The idea that uh I I've built this
technology that allows you to attest
you're a human. You're unique to a
community or to a transaction. You
demographically are who you say you are.
>> You built it.
>> My company.
>> Oh, yeah.
>> I'm a leader.
>> Okay. Yeah.
>> And the idea that uh
>> uh it's an anonymous system and once you
go through a launch, you can then be
reauthenticated. It's
>> the idea of trying to bring humans into
the loop where kind of to your point
whether I'm going to a website trying to
join the first person project as an open
source developer whatever I can use this
mind or similar technology to say yeah
I'm a real human I am unique but you
don't know exactly who I am.
>> Yeah that's awesome. Where was the the
core like why why did you want to build
it? Uh we got into it through a
relationship with meta actually. So they
were looking for a face verification
model. We entered their RFI in one.
>> They've been using a hypers scale about
12,000 times a second globally.
>> What is RFI?
>> Requests for information.
>> Oh yeah, they're terrible.
>> Yeah. [laughter] So we entered theirs
and we provided a model. They won our
competition and they deployed us and
they've been using us for account Oh my
god. Account unlocks.
>> Okay. Oh. Oh wow. That's crazy. You
know, I was locked out of my Facebook
account because I'm I'm a US citizen.
>> How did you for years?
>> Oh, I was I live in Spain now and I've
been there for eight years this month
actually and I lost my Facebook account
for 4 years because I kept like I travel
between and I didn't have a phone number
and I would try to contact them if
possible until they must have updated
something. Maybe it was three years
>> sued a lot and so three years ago
>> something happened because I recovered
it
>> very end of 2024 they rolled us out as a
alternative path to that
>> wow stopped it for me
>> and you you would have submitted a video
selfie
>> no I didn't I
>> I went back to the US
>> ID or something
>> no like I think it was still like it was
strange like just a combination of my
like my old phone. I probably got access
to like a really old email like the very
first email that I ever used it with
>> and then I think I connected my
Instagram and through a phone number the
connection because now they have
purchased Instagram and like the
WhatsApp and maybe it was like the
connection with what's up the phone
number unsure but finally got access
which which I thought like this is
terrible terrible terrible I don't
understand how like why is this so bad
but anyway I don't care about Um what I
care when you're talking about your
technology like I think it's super cool
like um when we think about biometrics
like I studied migration a lot like I I
grew up in Tucson so that's the quarter
town um and for me like moving abroad
going to Spain when I was doing my human
rights program I was like really focused
on like how with everything with the
African population saying what's going
on and you know we got really into the
studies of you know just I guess a
barrier example before go was
designated, you know, like the
biometrics at the grocery store, you
know, for me that was like so bad. This
is like terrible that like that like
>> what
>> is that how they pay?
>> That's how they were Yeah, that was like
their trans their right now was their
transaction to like get goods out of
like a shelter like grocery in a tent
which is like horrifying even begin to
consider it. That is the extreme.
>> That is so horrible.
>> Extreme version of non privacy
preserving measures.
>> Yes. Yes. Um anyway, you should you
should form part of our circle in
Gleonet, which um
I'd love to, you know, I think my boss
is coming in a little while.
>> I like that. Where are you? Uh, I'm in
North Carolina. The company's based in
Europe. Headquarters is in London and
our tech teams in Hungary.
>> Nice.
>> CTO's in Barcelona.
>> Oh, that's so cool. Maybe I didn't meet
him in one day. Um, how long has this
been around for now?
>> 20 years.
>> 20 years. You started it?
>> No, they got they met at Oxford, the
co-founders. I joined four years ago.
>> Wow. Okay. Whoa, that's a long time.
>> Yeah. And I always joke we've been
waiting for this AI renaissance to catch
up.
>> A like now is the moment.
>> Yeah. They got started in the context of
advertising with proprietary models for
measuring attention and emotion.
>> Okay.
>> And doing ad testing studies.
>> Okay. Totally different.
>> Yeah. And then I joined to lead a new
platform business. And when I joined we
were still focused on attention and
emotion but then identities.
>> A and that's like your bigger
>> that's where I saw the opportunities.
Yeah. to disrupt this surveillance
state, this dystopian thing that's
taking shape right now.
>> But like
I'm not knowing, right? But um Meta's
whole Rayban thing with the glasses and
wouldn't like from an out way far
outsider. It seems like Meta doesn't
care.
>> We actually So we actually won their
competition around the Ray-B bands. So,
our models were
>> they actually put them on rebrands
earlier this year secretly.
>> Whoa.
>> Without telling us, but um the plan was
to debut it at their developer event in
September, but they really messed up the
PR.
>> Oh, September.
>> They messed up the PR on it on purpose.
So, in Q1, they leaked a very dystopian
version of what the solution would do.
They said it would dox anyone. Just walk
around and be like, "Oh,
>> they were the ones that leaked that." Of
course,
>> that's what they do. They see what
happens like, "Oh, that's how bad it
is." has been 6 months no one remembered
but this time it kept ramping up and
that's very thought we're not going to
do that with the plan is what they
patented in their plan is actually
>> still doing it
>> no what they is actually quite friendly
it only recognizes your friends and
family doesn't know strangers
>> oh
>> and it would help people with like
disabilities
sort of interesting compelling use cases
I don't know why this is actually for
good and a counter to But how are they
going to fight that narrative?
>> They have to do better.
>> I feel like that's so far farfetched for
where we are.
>> That's why we're trying to help them.
>> That's nice. It's very optimistic. Uh I
do think
the public narrative is like we hate you
like terrible.
>> Just get a good president like 17
billion.
>> Yeah. 17 billion. Yeah. That's like the
first step towards them being like
tobacco companies.
>> Yeah. Yeah. That was pretty
>> led the way.
>> More to come.
>> Yeah. Uh why do we have to wait so long?
You know what? Like why do we all have
to wait so long, right?
>> All wait for cigarettes.
>> That's true. That is totally true.
>> Yeah.
>> 100 years or something like they were
saying it was good for your baby.
>> Yeah. Like or [clears throat] the
smoking on planes like you look back at
movies. Yeah. Yeah. Context does matter.
Absolutely.
So what is so your local product here?
>> Uh
those those terms work with you know
technically being here.
>> What did you do before this?
>> I'm like 17 years into product strategy
and innovation leadership
>> attemp.
Wow. What was your first job coming out
of like school when you started this?
very boring analyst
>> like
>> economic consulting and higher education
and social policy.
>> Wow.
>> Nerdy stuff.
>> Me too. But normally from the social and
behavioral sciences. Yeah. I've been in
tech now for like I guess seven years
since I since I moved to Barcelona. Um
but I wanted to be an attorney. Um
somehow I I met Richard at a Ricecon
event. Do you know what Ricecon is? Um,
Reichcon is one of the largest forums at
the intersection of technology and human
rights. And so a lot of the it's put
together by this nonprofit called AIS
now. Um, and a lot of like the good
players go to this conference to sort of
connect. Of course, the the other
players are also there. They usually
sponsor like a Meta or Amazon. Um, but
the thing that you said about Meta like
patenting like the nicer version.
>> Yeah, you can look that up.
>> Yeah,
>> people have done follow on stories
saying, "Oh, well, they just patented
this. This isn't as scary as we
thought." But it still sucks.
>> Well, mainstream media, right? They love
to play the narrative that like get more
clipped. Yeah.
>> If it bleeds, it leaves. Yes.
Did um like travel on Spanish and just
Spanish in Spain for very long at all?
>> I'm Mexican. I'm Mexican American. So
speaking Spanish is
[clears throat]
>> Spanish is different from Latin American
Spanish. And then of course because I
live in
Satalan and
I kind of understand it more so now
after you know picking it up but
like if you're talking fast like I'm not
going to really understand
>> and even just saying
when you say
>> yeah no I haven't picked that up
>> a little bit scared people
>> the jet
>> [laughter]
>> Scott
prices.
Nice to meet you.
>> Made sure.
>> Great presentation.
>> Thank you. So, how long have you been
here from Singapore?
>> Yes, sir. What's that? And you're like,
okay.
>> No. Okay. My brain was like all I was
trying to fall asleep.
>> Yeah, some damn Red Bull.
>> You're really good at holding it
together. How would we know?
>> I would be a mess.
>> I am a mess and I did not do what you
did.
>> I'm a mess. I'm a mess inside.
>> Yeah, but you you are you like German?
Are you kind of all around the world all
the time?
>> I am. Yeah.
>> Yeah. Probably more. Like last year 197.
>> Wow.
I I have other hats.
>> Yeah. So, you're like essentially the
pilot. You get to sit way up there.
Imagine your rewards.
>> They look
That's
true.
Once on Christmas Eve, I got stuck
somewhere like the airport like you in
like airport shutting down flights.
Christmas
and kids
sometimes my dad come with me just come
and went to the store and said there's a
flight taking off and got USC we kicked
other people off we have USC
I'm like
>> that's
that's where that's the status where you
get upgrades and there status where
I've got
They will guarantee you a flight a seat
no matter what. They will kick someone
else off which is a shitty thing to do.
>> Badass to have that.
>> Yeah. Yeah.
>> Where are you? You arrived this morning.
>> I I came to London yesterday.
>> Oh wow. Where can you
>> North Carolina? Okay. So east coast.
>> Yeah. And I'm doing a cool hack I got
into in January when I came from offside
at Oxford. There's an hourly hotel at
East.
>> Ah. So I show up at air hotel and I stay
room for three hours.
>> Makes you feel
>> Adam.
[clears throat]
Zpp.
>> Oh, awesome. He reports to
>> Oh, cool.
>> Reports to Adam. Dennis has Yeah, he's
>> he's a deep guy.
>> Yeah. Yeah. Hey, by the way, I was a
nuclear physicist and no one's
surprised. Yeah. Yeah. Yeah. Yeah. He's
got his own cyclopron at home and we
keep waiting for the day where we see on
the news and be going, "Are you
surprised?" Like,
>> no.
>> Yeah.
I'm surprised.
>> He's very excited about what he's doing
as well. He's one of those guys that
>> if he's doing something he doesn't think
is like really hard or um really
worthwhile, it's hard to get him
motivated to be honest. But with this,
he's just like, "This is what I want to
do. This is what I want to do." And
yeah,
>> he's very
handsome.
Like, I want demos. I want things to
show people.
Awesome. Yeah.
That's pretty much where we're at is
zero knowledge protoc.
>> You didn't by chance pick up my
chocolate bar, did you?
>> I don't know where I put it.
>> You picked it up. There's nothing.
>> Yeah, I thought I did.
You put it in you stashed it everything.
>> Yeah. Okay.
>> Did you eat it by accident?
>> I don't think so.
>> Makes sense. Scott first opening
that
>> I'm still very much drinking from the
fire hose trying to have things come
into focus.
>> It's just more if it's like thumbs up
then let's just go. But if it's like no
no no there's a misunderstanding of the
use case and how it can be better to
know that now
>> then this will become like the north
star
>> and then like heart is over that as well
everyone gets a line to that one
that
What's the next crazy thing you're
adding to agent whatever?
>> Uh, no, I'm working on Genie. So, how
you doing?
>> I've um it's connecting the two of them
together.
So, uh I can now here is agent stream.
You'll see there are 23 services. If I
type in Genie, there's nothing but I can
go over to Trust Genie and I'm logged
on. I've got organizations account
building and everything.
>> So I want to enable LM safety. So I do
this
and
>> that's cool.
>> In a second it will be done. Okay. So
it's done because there's nothing to
spin up.
>> Yeah. Yeah.
>> And then I go
>> when you say there's nothing to spin up
>> because the instance is already running.
It's a surface. It's a onetoone mapping.
>> This is multi-tenant.
>> Yeah.
>> You've created multi-tenanted host.
>> That's that's what I'm Yeah, I got you.
>> Cuz it'll cost little bit. Yeah. Yeah.
Yeah.
>> 200 users.
>> Absolutely.
>> So that's going to give us the
>> Okay, that's pretty cool.
>> Yeah.
>> So the bundles are really just surface
features. We'll curate them and call it
a bundle. And the names can be
completely separate because no one's
ever going to see it. Interesting.
>> So we can say I want an OPA policy.
>> How do you do the isolation between them
or just
>> different systems? What this the trust?
know that if I you know if I go into
trust union as well and spin up
something
>> um because every ID that's generated has
a pattern which contains your account ID
your project ID whatever and it's
checked
>> this is actually you hit on exactly the
problem because the back end was never
built for that so I need to
>> make sure that it's not possible
>> it's in the VTI stack the way I solve
that is why I just religiously only use
TSV or DICOM which is I accidentally
send the wrong message somewhere M where
it doesn't matter. You can't do anything
with it. Yeah.
>> Unless you got the key in which case
>> but as an administrator if you log into
the back end of a gateway whatever you
have full like the default you have full
control of drag things and press save.
Well it's all fixed.
>> That's what you're doing there as well.
Um yeah yeah yeah it is only like two
days in so it's still a bit brittle but
>> what I think
>> it's okay to be pragmatic and just say
if you don't like them
>> then you upset
>> yeah most of my family
it's really
you
But I guess it gets cold in North
Carolina.
>> We have four seasons for sure. Winter's
Winter is hilarious. Somebody who's been
in the Midwest winter is really like
North Carolina.
>> North Carolina will get dusted.
>> Yeah. Um
>> but because they don't have
infrastructure, they shut everything
down.
>> Yeah. But then if you do catch people
trying to drive through it, they have no
idea.
>> Yeah,
>> it's crazy.
>> And the first time I experienced that, I
thought I was in a different dimension.
Like I was steady and doing all the
things. Everyone's literally spinning
out. I said, [clears throat] "What's
going on?"
>> Yeah.
>> Take your foot off the gas. [laughter]
>> Yeah. Yeah.
Yeah. Come from the desert, so not
humidity.
Awful.
It's really humid in
>> Barcelona
from the dry heat.
Yeah, you can definitely don't have good
>> is why I think for both of us we've got
to do a bit of a time out and just watch
videos and showcasing
>> the original
>> there's so much gold and like like that
whole thing I just actually get it
properly structured with
layer
when you start layering that
now actually
>> working. So you can use trusting but you
don't have to do the case of trust like
this.
>> Hello. Good to meet you in person for
>> Yes.
Adam dog. Hello. Good to meet you.
>> Good to meet you too in person.
>> Excellent.
>> You're the ones on the train, was it?
>> Yes.
>> Thank you.
It's not just presentation.
of one of the forces behind
>> one of
hope it's more
ready
people talking about
something
experience that he just thinks about.
>> Yeah.
Yeah.
I don't know.
Yes, sir.
>> Yes, I was. Yeah.
This is
Very
you're
like
fraud
and the way that they had
the problem to verify me is super lame.
It's like a interview.
>> Is that verified? I think it verified
that ID me or something and like a
person the person has you hold your ID.
>> Yeah. Videos
>> sketchy, right?
Guys, you saw World Hunger and Peace
while we were gone
>> twice.
>> Thank you. Did you take notes?
>> Actually, not World Hunger because I
bought myself the chocolate bar and then
I lost it. I don't know where it went.
[laughter]
So, quite the opposite.
the same person. Why are you deciding
who that really is? Yeah,
>> you can get your computer on that if you
open a web.
>> I think I see if I open a web browser
and click.
>> Yeah, you you pick with the spaces
Wi-Fi. Pick the spaces network,
>> open a web browser, and then it won't
load the page you ask for. There'll be a
little click here top left. You click
that, and then it opens up. You
just face to That's what I did earlier.
How do you say weird Linux people?
>> You know, I actually don't know how you
would say that.
[laughter]
>> It's not you. It's me.
Okay.
>> You mean you talk to somebody and they
have Yes. Okay.
Now I understand. Okay.
>> But we need
Yeah. So you can
connection
that
we have a strong for tonight.
So I have
recommend
some of them working on this. We could
try to create a framework so that each
mistakes.
>> Yeah, it's interesting.
>> Gary loves cricket so he'll be right
into the sport.
>> I was at a business in Palm Beach,
Florida
>> years ago. Accountant guy. He's actually
rich dad. You ever heard of
poor dad?
>> American book. This this is a guy was
written about this guy's the funniest
account I've ever met in my life.
>> But he says you know the language of
business is account
language but he went and read
>> a cricket play to the American football
crowd
>> and he said they might play understand
cricket four,000
put them up. This is going through when
people in the audience are dying
laughing.
>> People you follow
they speak the language you know when he
goes to Australia he does the opposite
football
installed
>> this thing
that would be in my browser.
or Carly tell us it won't work.
>> Have you got the same problem you have?
Do
>> you want to see something?
>> But what is the thing that I click on?
>> It'll tell me like in my notification,
right?
>> It'll say you have to log in.
there
connected
>> open go to my bundles
>> and
have been just a surface
here.
You're very
>> judge and jury
different
bundle. The actual content doesn't
matter. Like I'm starting
up section.
>> Yeah.
>> I mean I just tethered it to my phone.
>> Yeah.
>> All right. Let's do that.
>> So she attacks her brother.
>> See this screen.
>> All right.
>> Yep. So that's what
>> I say
for complicated.
>> So we get to decide what is the simplest
possible thing
>> and then it just gets turned into a
circle.
>> Oh. restaurant
and the gateway everything
>> there is no automatic connection
if you take that
>> that will be all right at the moment
it's proxy but that'll be a fleet
>> but you can
start up again.
>> So, this is what I'm working on now is
making sure
>> anyone who's got the Zoom up, if you can
just keep an eye on the chat questions
that are we still have a couple folks.
So, we have uh
>> we have this place till 5 and we want to
uh you know cover a few more things in
our in our last um uh you know 45 50
minutes but also leave time for
hopefully folks got time you know chat
but um uh then the idea is anyone who
does want to go to dinner um uh Andre is
researching
restaurant options being a, you know, a
sort of local close to local.
>> Close to local, you mean close to local
here or you mean close to local food as
it gets?
>> Uh,
>> someone who actually Yes. Actually, I
guess Martine is the other almost close
to local. I mean
>> local
[clears throat]
>> two two people are better equipped than
me doing their stuff
>> because of their generalizations.
>> Please do feel free to recommend a
restaurant for anyone who wants to then
uh water down to dining after.
>> Well, do you do do people want to stay
on this side of the lake?
>> Well, I wanted to go get pick up my bag.
All right, we have an hour to talk about
cons substantive stuff. Don't worry
about that. I'm cool with that.
>> All I was saying was anyone who does
want to check into that while we're
doing this. Okay.
>> But yes, we have actually a little less
than our let's say 50 minutes. So, um I
have some slides that sort of summarize
what the state of play is right now. Um
and and a few topics I want to bring up
just for all you know for folks that are
interested in decentralized trust graph
verifiable trust infrastructure and what
we're doing with the first person
project and the cooperative um so we can
do that to sort of start up a
conversation but I do want it to be a
conversation because this is a project
and you all are contributors or um um
you know directors of how that's going
to go forward. So, um, [clears throat]
some of this is just, you know, to make,
you know, I know a few of you are new to
what we're doing here, so I just want to
make sure you understand where we are.
So, we really kicked off sort of
publicly at a first person project um,
meetup a year ago and now that we have a
full room, how many folks were actually
at that meeting?
>> Okay.
You gave a talk there. Exactly. And
Martino was there. All right. So there
like six of us here in the room and some
of you were online. So in any case, uh
it was rather hot.
>> I was here. Yeah. Yeah.
>> Yeah. It was it was very hot,
>> but it was still uh it it was great and
it gave us a a good uh good momentum
going into GDC. We had no idea what the
reception would be for the few sessions
[clears throat] we had planned there.
And it was I thought it was great. There
were a lot more interest than than I
expected. That's one of the reasons
we're we're back. So,
>> beyond interest because like this
because here I am at GDC again like
beyond interest how many of the people
who are interested ended up following up
beyond just saying that's cool
>> like in terms of results. Okay. So, we
have some people who joined the group.
>> Yes. Well, last year
>> it's one of the reasons I have this
slide up.
>> Okay. We went from only having a
actually at that point we actually
trusted we could approve this new
working group but it wasn't starting up
till September
and we hadn't even uh engaged diff to
approve it being a joint working group.
Now we have I'd say there's roughly 30
folks attending once a week the the main
meeting. We have three dedicated um uh
task force meetings that are also
meeting once a week for an hour. And all
seven of these uh task forces are like
>> moving. Yeah.
>> You still haven't approached DI about a
joint working group though
>> about a
>> a joint working group
>> for [clears throat]
>> I don't know. I would know if you'd
approached Dick, right?
>> Oh, no. That happened last last
September.
It is a
>> Oh, the Oh, the joint work group. We've
already had Okay.
>> Yeah. That no that happened is before
trust approved it I think in June.
>> I was speaking
>> but we said we weren't going to start
out till September and then we started
September. Okay.
>> Yeah. And so yeah no it's a joint
working [clears throat] that's why we
have members from both def and trust
people.
>> Awesome.
>> So anyway oh go ahead. May May I do one
thing? The background is blurry and this
hurts the video.
>> So if we don't do that
>> because then
there
>> Thank you. This is why we have technical
experts for this group.
>> Good catch. Uh so yeah so this is again
why I put this slide together to be I
mean there's just huge and I'm going to
say this so I've been doing um
based work [clears throat] on this
standards in this area on this
trajectory for 34 years I've never been
part of a standards effort that's moving
as fast as this one um or has has as
many and part of it is this that we
adopted this idea of code first with uh
with the development of these standards
and uh and you saw you know I'm I'm
pointing at you know the folks that have
been leading that's been really awesome
that's that's
[clears throat] why
next slide um
yeah no actually so just on deliverables
from those groups okay first two now
have working draft specs and when I say
working draft I mean full uh you know
trust RP standard template that we
developed finally after after you know
six years of working on that stuff and
um these are these are pretty robust
working drafts already. I mean they're a
long ways from okay being final ready
you know for 1.0 We own all that, but
we're also just ordering up um uh the
the repos for ZKP verifiable data
structure agent names and thanks to
Daniel and um Nikki who's not here.
She's still on her sbatical and
[clears throat] Margaret Marguy Noatne
who will be here for GDC but she's been
hiking in the dolomite since she gets
here in Geneva tonight. Um we have a a a
full you know leadership and a lot of
interest in the human trust experience
which
[laughter]
>> it is and I I will say one thing I don't
know I didn't see Seren on there that
last risk and harness prevention he's
built I don't know what you call an
agent harness for
>> yeah a risk and harm prevention AI tool
that looks
complex multi-repository software stacks
and then what are vectors of attack or
misuse that they could be used for.
>> Exactly. He's applying what what risk
assessment hard prevention which was our
first task force came up with in terms
of analysis and he he's built that and
it's already resulted in improvements to
these uh for specs. So anyway, it's just
it's moving and it's in this next year
it's going to be I I expect we're going
to have filled out all of those and
we're going to have infrastructure up
and running even before these specs are
all final.
>> [clears throat]
>> So
uh another
story there's one person in the industry
will who will go unnamed not presently
in this room who has assaulted me for
the best part of my career. Where's the
code? Where's the code? You're always
talking these good ideas and sometimes
even good standards, but where's the
code? And my favorite thing about this
project is
not only what you saw here, the open
VTC, and again, I'm just blown away how
fast that's moving, but in the last
couple months, there's a second
trust stack based on lib P2P being
driven by um Erica Duni, I believe
that's how you pronounce her last name,
and Shannon Bailey. Um they're based in
California. They're both also Wikipedia
alums. Uh, but they wanted to to to bend
to the edge. And we have another member
of that team now called the Trust
Stackers sitting in the back of the
room.
Uh, Martina, is there anything you want
to say about the uh this this virginly
new uh uh uh trust trusters.com is now
the site?
>> Yeah, the site uh you can uh check it
out. this uh trust stackers.com.
Um there's a mailing list you can join.
Trusters trust stackers one word.
There's a mailing list you can join. Um
there's also a signal group I can share.
It's not up there but I can uh share the
QR code afterwards for us who like to
join. And uh the next big goal will be
IIW
uh where I intend to have something to
present your thoughts maybe even in the
decentralized transcribe working room
like two three weeks before and then
have some sessions that go into the
details. Um, so yeah, it's been
becoming more and more.
We're like, I don't know, seven months
behind
the other stack. But the goal definitely
is to have it interoperable. Um, so that
we can also, you know, benefit from each
other and make this entire thing bigger
and it's accessible for everyone. I love
the fact that now they're going to be
these two stacks. It basically um forces
the the question of interoperability uh
trust suite which we need anyway. You
know, we you don't have all
infrastructure without it. I actually
think it's one of the things that might
be foundation has leaned into and done
pretty well for for quite a while. Um
but we need it if this infrastructure is
going to get to where it's going to go.
Um, a reminder actually to both teams on
that, make sure you get into the um, IW
demo queue at the start because it fills
up every time and we missed out being
able to do demos last time because we
weren't in the queue. I'll try to
remember that. Um, but yeah, no, that'll
be that'll [clears throat] be awesome.
Um, by the way, uh, Martina was not able
to make the call, but, um, I had a call
with, uh, Erica and and, u, uh, Shannon
sort of prepping for this and and and,
uh, discussing various [clears throat]
things about their plans for, uh, the
P2P trust stack and, uh, sort of a show
of how determined they are uh, how much
firepower they bring to the table
uh, is the Burning Man um uh vehicle
that uh Shannon was the primary
architect for and and their team built
together and I guess it
they were one of the very early uh
burners uh and this vehicle eventually
was donated to Burning Man and is still
still does the rounds there. So, and
that is a real fiveheaded fire breathing
dragon. So, if you don't think these two
women [laughter] are serious,
this is in I can't remember some some
article about the burning man. It's one
of the icons like
>> um Yeah. Okay. So, they're serious
burners.
>> They bring the fire.
>> Um we were talking at at coffee. It's
sort of like okay what's the actual
human trust experience going to be of
using this uh infrastructure and uh even
though they can't be here today um this
key ring is a being driven by um Alberto
Leon and Brendan Miller uh who are they
were for the Harvard applied social
media lab they got refunded and now it's
the Harvard applied technology lab um
it's now associated with the like uh
technology and business school whatever.
Anyway, they still have a major
sponsorship at Harvard
Harvard really likes what's happening
here and wants that to grow and expand
and uh so what currently key ring you uh
Alberto is giving a talk on it. I I'll
I'll list that um later on.
[clears throat] and uh and both of them
are coming to the um
uh to the the um Linux the plumber
summit and OSS um Linux open source some
Europe in in prog in in first week of
>> I just say a shout out for Brandon and
Alberto for DTG every issue now that
we're raising from a build perspective
they independently co-build in another
language stack and verify
>> so implement aspects. Yeah, that's being
really helpful of just clarifying that
what we see from one perspective matches
another build.
>> Oh, totally.
>> I also want to give them a lot of
credit. They did the the first
>> uh graph of the credential spec.
>> They've been staying right on top of it.
The editors teams are really leaning
into this stuff. Uh it's setting a
really high bar for all of us and
>> very easy to work with.
>> Yeah. Yeah. It's a great uh great team
and they they are getting personally
quite invested in where this is going.
So uh it's a really good sign
[clears throat] and uh there's another
interesting potential mobile app um
called Union. You can read sort of this
is a set of bullet points on the GitHub
of um Phil Broedale who was the founder
of Second Life. And I'm not here saying,
"Oh, he's ready to pile in and, you
know, totally deliver a uh uh, you know,
DTG enabled app." He, uh, spent half a
day with Erica and Shannon. Uh, this
was, I think, in early June going over
what his requirements were, and they had
been working on the P2P trust act to see
if they can supply what he what he needs
to be able to do all this with EPG. Um,
but he's pretty serious about this app
and he's got a pretty good track record
of uh uh one thing [clears throat] that
I learned talking to him is there is
still um
uh in Second Life 20 years later a
billion dollars a year in the economy uh
um of that. Yeah. So, the metaverse,
you know, a certain Z guy never
produced, but Second Life is still
producing. Uh, yeah. Okay. So, there's
that. And then, um, people ask about,
well, what are what are the other apps?
I got had some great dialogue in New
Zealand when people were saying, well,
what about this, what about that? And I
just wanted to list that we for quite a
while we talked about um uh agent agent
pages uh and using VTAs as simple
contact agents. Really it's a pretty
simple function but it's your policies
now. It's entirely independent. There's
no LinkedIn or any other mediator in
between. I can hardly wait to get that
to market. The irony is that our best
propagation vehicle for uh for folks
getting on this could end up being
LinkedIn, right? As post folks
announced, hey, in addition to my
LinkedIn page, here's my agent page,
right? Um
I've been waiting for like 25 of those
34 years for what I personally have
always believed is a killer app for this
stuff, priority messaging, right? And
just how many of us are so delused with
messages? My ex-wife. Every time
>> every time you text her, this is really
going to work.
>> Which one was it even? [laughter]
>> It's
somebody sent me an email. I didn't know
it. I didn't do anything. And I'm like I
go to her inbox and I'm like, "No
wonder." Well, it was important. like
[laughter] yes, but email doesn't know
it's important, right? She needs she's
just a perfect example. You know, how
many folks and how many businesses would
like to have a private channel with you
where they know it's not fishing and if
it's priority, they're going to get it.
>> I
see you.
>> Welcome.
>> You have to do an introduction before
you can even sit down.
>> Okay. Uh, Richard Wit just flew in from
San Francisco and I'll be speaking
Wednesday on Tuesday.
>> Tuesday. Oh, no, no, Wednesday. That's
right. That's right.
>> Today's Monday.
>> First of the two days of the two
sessions.
>> I know my days are off. Yours should be.
>> Anyway, really pleased to meet you all.
Sorry I'm late. Uh, just, you know, a
bit. author of
>> a little book called Relieving the Web.
>> Oh,
>> found the need for new governance of uh
viant fiduciaries and personal AIS
>> and first person cooperative be a
perfect building in my mind.
>> That's why in the 30s sorry to interrupt
but
>> no I'm just really glad you can make it.
>> Yeah, I'm really happy to be here.
>> By the way, trains have been late.
[clears throat] People have been um you
know
>> Yeah.
>> trickling in and it's all good. It's all
good. We're just We have about a half an
hour left, okay? And we're just
basically going over what what's been
going on with the uh the project, what's
the state of play, and where's it going.
So, perfect perfect timing.
>> In fact, [laughter]
literally, he walks in, as I'm about to
say, and then there's fiduciary.
>> Oh, right. Oh, sure.
>> I mean, were you like waiting until I
got to that point
>> dramatically? Yeah. For 12 minutes
outside the door.
>> Yeah. Yeah. It was like, okay, okay, I'm
going to wait for that. [laughter]
Seriously, this is something that that
folks will die. They heard us give
several talks about this. That's where
uh I last saw Richard in person. And uh
[clears throat]
I'm understanding that we've only seen
half of the uh the amazing
[clears throat] stuff coming from
Infinity because the other half they
won't show us yet because it's too top
secret.
>> Ask that man.
>> Yeah, it's these two right here that are
worth.
>> We have no secrets.
>> AI. No, I'm I'm It's a squirrel secret
stuff. But [clears throat and cough]
I will say this at the February um um
summit on human agency that we had the
the uh Affinity app which there was
called H2 Connect um you were connected
with both people and AI agents in one
interface one they could be part of the
dialogue and uh I'm hoping that's where
this is going to go.
>> Cool. The big thing Richard's gonna add
after, you know, he's actually a real
lawyer at the table is
>> apologize.
There goes any conversation.
>> I was just going to say, well, this is
>> this is going to get really expensive
then obviously [laughter]
>> what I love is the fact that he was
inside at Google for 13 years,
>> right? And then he broke out of the
cage. He's [clears throat]
>> probably You can export yourself from
Google. [laughter]
>> Exactly. Um [clears throat] anyway, I
think there's a lot of potential there.
Last one up there is
the a more recent subject but one that
um is getting a lot of attention because
I've been working on the challenge of
funding for the first person block for
the first person that one of my first
person project since I left Jen which is
now 14 months and I gave myself six
months to get that done. Um
the the the thing that bought us more
time I want to acknowledge was Affinity
helping us out in the early part of this
year. Um and that really helped us get
the Seattle workshop, the the February
events uh with the Linux Foundation, but
we're still going down that um that uh
path. And um
the aha came this summer when not only
was the the uh open BTC starting to look
like whoa, you know, this these trust
tasks were really they were multip I
mean we're up again. What was that
number again?
>> 350
>> 350 trust tasks are now in the registry
at trust.org. Okay. So it's Yeah.
Doesn't that figure worry you a little
bit down?
>> Worry me. Yeah.
[laughter] Anyway, um
also when the P2P trust act work was
going, I found out that um Erica had
separately been working on in a separate
app, a crowd a crowdfunding app that she
recognized she could basically uh VTA
enable and suddenly like, oh, that's an
app that can be built right into VTA.
Imagine that you're joining for the
first time. uh a trust community, we get
an invitation from someone, a person or
from the community, right? And in the
process of joining and getting a VTA,
you're getting a wallet with hooking it
up to whatever just like you do, you
know, when you first get one of these
wallets, you give it credit cards. You
you you you enable it with means of
payment. Bingo. Now it's it literally uh
a click to join a crowdfunding
and if this is an app then any BTC any
BTN out there can do a crowdfunding.
This changed our perspective on how much
we should be looking at other funding
sources versus bottomup funding for this
stuff. So, [clears throat]
so now I'm just going to briefly let you
know what so what is the state of play
now with first person first cooperative
first where are we going with this idea
and
so this again just background to make
sure we're all on the same page um
people hear this you know oh are you
going to create a cooperative we created
a cooperative we we we did about nine
months worth of research and we're very
surprised has to find that the most
progressive cooperative law in the world
that at least fit our needs was not
outside the US. It was in Colorado
largely due to these two law firms there
that worked together quite a bit. All
they do is social enterprise and they
actually help work with Colorado this
like 12 years ago to instantiate a new
thing called the limited cooperative
association or an LCA. It's a hybrid of
a conventional patron uh patronage
cooperative and um an LLC. So you can
have investor members that actually get
shares just like you would in a C corp,
but they're there's no unless the
cooperative is designed to have an exit.
Some of them do have exit to community
as an option. Um they're typically just
repay a multiple of their investment. So
it provides a means for cooperatives to
get the seed capital they need to
actually you know uh grow a new
business. Um but they don't participate
in governance. It's pure funding. The
patron members are the ones that
actually uh govern the cooperative. And
that was our whole goal because the idea
was if [clears throat] we were going to
establish a VTN although it's clearly
now a btn of VTN's
um for where the the the member
communities and network said we're going
to have common governance for person
the paper that we so widely site around
that. Um [clears throat]
then
how do you want to govern that? how do
you want to govern as as a global public
utility? And you know, based on the time
I've spent in different governance
options, it was like, you know, if it's
going to work for people, then people
should be the member owners. Um, so
[clears throat]
that's what that's what we set up. We're
in the process of putting in place. We
basically started with uh uh some
classic, you know, placeholder bylaws as
we figured this out. We're in September
should be approving the first bylaws
that are really underscoring you that
will that will actually be operational
at which point now we're ready to
actually start spinning up BTTS VTN's
and having members that will then
>> I've got a guy that can help you.
>> Yeah. Yeah. Exactly. Excuse me. Believe
me, a lot of interest in that charge you
$30. So if we go back to this picture
and some of you who weren't here at the
outset but you probably seen this before
[clears throat]
>> early on we had as I as I put in the the
newsletter we were thinking of these
btns and like okay they're going to be a
couple of those like first person
network they're trying to solve this
broad stuff after I trip to New Zealand
as for those who are here to listen to
Andy uh uh Higs
I would I step back and oh no no no
there are going to be many VPNs right
and uh I did my own research to say how
actually did that work on on the uh you
know with the [clears throat] internet
routing and uh and discovered I did not
know about autonomous systems or as I
brought it up with Glenn Glenn
immediately goes oh yeah internet
handles autonomous systems and uh
[clears throat] that I learned from the
Wikipedia article there are now roughly
120,000 in the internet system. They in
turn have their own
>> tree out. Some of them have hundreds or
thousands of lands that are part of that
autonomous system.
>> I didn't, you know, I'm not a protocol
architect at that level. I didn't know.
But that's that's I think a much more
accurate picture of what could happen.
So, so [clears throat] now it's much
clearer. Oh, but the first person
cooperative, it's not just people or
VTCs. [clears throat]
We want to have VTN's as members. Um,
and and they're they're the ones that
probably have the biggest stake in the
cooperative being successful.
>> Okay.
>> Oops.
>> One thing I could add to that drummer
would be
because a lot of this is now built out
up to just under the VPN.
Nothing. There's been no red flags as to
why this architecture doesn't work and
nothing has been thrown out. I just want
to say that because that's a key point
that none of this has actually been put
together before. And so one of the
things we're always pressure testing is
there a better way to do this and can we
actually get rid of one of if you can
get rid of a layer that's the best thing
you can do architecturally but actually
all the abstraction points that are
there are there for a very important and
legitimate reason and that's being
reinforced as the build goes through. So
I'll just say that's an important side
effect that's being tested literally
daily um on the spec side of this.
>> Yeah. [clears throat]
And
the the both the the powerful thing and
the risky thing here is that
we're getting down the road here with
again specs with code with plans for
governance
in this next year.
We need to instantiate this thing. We
need to actually get VTAs and V and
VTC's up and running and the first
VTN's, you know, happening out there.
And [clears throat] that's going to be
the big difference. If we're here a year
from now, I don't know what's going to
happen with GBC or whether we'll even
decide that's an important milestone,
but that's what's coming up.
[clears throat] And so
again, what that the last thing I'm
going to tell you about here relative to
to this is where we're landing,
especially after the feedback from New
Zealand and the fact that they're
looking at several VTN's that could
happen in New Zealand by itself. Maui
want uh sovereign uh infrastructure.
There's a big movement for uh Maui data
sovereignty. So the reception to our
message down there is just it was like
open arms like this is the only thing
we've seen that actually would work
versus the the digital identity um
options they've been looking at for the
last 10 years. [clears throat] So and
that's that's just one market. Um so the
aa went on it's not just that we could
crowdfund for firstperson network we
could crowdfund multiple networks and
this collaborative or cooperative
crowdfunding it's just it's we're moving
into a new paradigm. [clears throat] So
this is a table and a doc that I've
written up some of I've shared with some
of you. I'm happy to share it with
anyone who's interested on this
cooperative crowd campaign with what we
have sensed are the best options right
now. I'm going to talk about this one in
just a minute.
We know when we're going to um the Linux
Clumber summit a month from now that Jim
Zan's plan from the outset had been it's
not we're not just doing the kernel. He
wants us to do the kernel first because
they have a web of trust and if they
adopt it's going to be clear sailing for
they're already lining up Kubernetes to
be the second community that we go to
and [clears throat] then
it's a Linux foundation VPN covering all
their projects. They build it into um
LFX, their platform that's based on
GitHub. Jim's going to be here this
week. We are going to talk to him. Uh
turned out I'm on a panel with him. I
didn't know that. But we're going to get
Danielle said we're going to get some
time with Jim. He's also going to be at
home. So, so we're really going to
cement that um as sort of our anchor
candidate. [clears throat] Um
there's a lot of interest here. I didn't
want to list anyone there because the
thing is we don't tell anyone else. They
need to say, "Oh, we want a VTN. We will
put it together." But um Andy
[clears throat]
uh Higs is already assembling the folks
down there that would want to put
together um at least one indigenous BTN.
Go ahead. You're gonna ask something.
>> Yeah. Um, my question is, okay, this is
great and I'm excited about the
crowdfunding. Is there a more long-term
sustainability plan in terms of like
paying per member, you know, like this
is kind of passport as a service for,
you know, identity card as a service.
And so the initial crowdfunding, I can
definitely see it coming from the people
who want to give it a try. But then is
it would it be something like okay if
you're one of the initial crowdfunders
you'll get this many identities for free
and then I don't know are we thinking
about a longer term sustainability plan
not just crowdfunding. So yes, and the
big shift and I'll talk about a minute
is recognizing that
every btn and the the the stakeholder or
population that it's serving can decide
for itself. Like again I was in sort of
the mindset of oh first person going to
figure this out as a cooperative for you
know all the folks we're working with um
and we'll come up with some model that
works you know globally right I now I'm
like no no we don't have to do that we
can let every bn figure out its model
what what really convinced me about that
is malry approach to how the Mauy want
to do this all the way down the
economics that's their business Right.
We should The only thing is if they say,
"Yeah, we want to be recognized as
issuing personal credentials."
Then they decide to join FBN and that's
all that's involved. There doesn't have
to be any economic relationship there
because if they're self- sustaining and
they figure that out, fantastic. Now,
that does mean First Cooperative has to
have a model and I'm about to talk about
what might work for us. But this idea
that each VT I mean um one of the things
would be uh the other thing that's come
up is rather than think at the level of
you know you know member states and
these larger organizational units cities
cities are
perfect for this stuff. Um, one thing
I'm I'm not talking about here today,
but I would just will share in New York.
I'm going in uh on on October 20th to uh
be part of a a one day thing at the uh
it's called Green Build. It's the green
US Green Building Council has an annual
conference and like 500 architects
there.
It's all about using AI with smart
buildings and the trust component there
is it's just a major it's like the
missing piece. I didn't know they had a
whole Linux foundation project on
automation for buildings.
They now as it's getting AI, you know,
AI enabled, they need the trust
component. An architect attended a talk
I gave in in uh uh in Los Angeles in
March and got right back to me the next
week and said, "Could you give that talk
at our next online conference?" And I've
now done it twice. So
>> [clears throat]
>> um
oh so his thing was it's not just a
trust architecture where every green
building is a verifiable trust community
but because of the interoperability you
now have a a a clear path to a smart
city where the buildings can you know
there are a lot of things that you got
you know floods or first responder
things or power conservation where they
need buildings to collaborate and all
all the owners together. So I I didn't I
wasn't even thinking brain buildings
when we started down this path and it's
like fantastic. So um anyway, even in
New Zealand, we started talking about
what about just tackling a VPN for a
city like Auckland, right? There's a
couple million uh people involved there.
When I went to Melbourne on the way
back, they said that's the best way they
felt to start over in uh in Australia
because there's the nice thing about a
city is people actually live in the in
the city. You can have first person
relationships that can be verified, you
know, throughout the city.
>> [clears throat]
>> So
anyway, I'm just I'm I'm putting these
out there as so you know what the
thinking is about how this stuff could
actually get off the ground. And of
course, what about Zurich? What about
Geneva?
I mean, I don't know how many folks we
actually have that live here, but Well,
half a million.
>> Say again.
>> The country of Geneva is half a million
and half of that against city.
>> Oh,
>> yeah. So, it's not it's not many people.
Okay.
>> I don't think the number is as important
as the fact that it exists in a trust
network. Like I was thinking of a model
where like a a forest
>> uh which is a national park could have a
verified trust and a trust pass as I
went on a hike right
>> and bio regions
>> bio regions voice to the nature through
this. common interest and and and and
therefore intersections that are
>> are valuable to have to be able to
verify. That's
>> obviously more people helps with the
adoption, but yeah.
>> Yeah. The River Dawn Project is trying
to do something like that. Makes a lot
of sense.
>> What
>> there's something called the River Dawn
project and they're doing a project
where people make their commitment to
the river like I'll visit the river or
I'll figure you know and this would be
perfect for that.
>> Yes.
Andy actually Andy Higs is there's a
similar thing uh in already started by
by Malry in in New Zealand for
conservation of their lands and he
thinks that might be the the best
starting point down there.
[clears throat] So anyway again I'm just
sharing these sort of plant these ideas.
Um I'll point one last one which is this
idea of uh the founders network or
founders btn and uh Martina is going to
recognize these diagrams because we've
been trying to figure out for the
cooperative how do we be decentralized
right how do we practice subsidiarity as
a digital cooperative because we're
trying to maintain this utility but the
last thing I want to do is centralize uh
control of governance so how do you do
that so we have these ideas of okay well
how do we how do we provide a way for
someone that's not in this room that's
not connected to us to be able to say
well I want to be part of that network
and u so [clears throat]
the idea of first person circles is oh
okay go get a set of and the number
seven is somewhat arbitrary um maybe
Martine has come up with really good
reasons why that's the best number we're
not exactly sure but this is an example
of seven but the idea is some founder
gets six other folks together. They all
need to know each other because the test
which the VTA will we we need to
basically build well [clears throat]
a VTA for a VTC that will do the test
everyone has
>> that's already exists. So when we show
the VTC there's a VTA behind it already.
>> Right. Right. But then the policy would
basically be show me credentials that
everybody knows. Right. It's not it's
not a big challenge.
>> [clears throat]
>> If that founder then could get an
invitation from another founder, it's a
way to start to build it organically.
But what if you have one of those where
none of the founders know any of us, but
we want it to still grow organically. We
want an even stronger trust route. And
that's the idea of founder circles.
Great. Go take your six. They have to
fill out their first person circles. Now
you've got 49 unique individuals. That's
the idea is everyone has to get six
people. Right now you've got a large
enough essentially group trust anchor
that if the cooperative provides way for
them to meet or get introductions to
other founder circles, we can start to
grow organically.
And [clears throat] the one thing about
the founders network is to your point
about sustainability. If you want to be
a founder and get a founders card as a
verifiable credential from the
cooperative,
it is an annual membership payment. Um,
and so the math is we're talking like 10
bucks. And so if founders network grows
enough, we'll s be sustainable by just
that one VTN as a cooperative. Every
other VTN can have its model and we have
sustainable infrastructure.
One model
wide open to better ideas. Please come
talk to us. If Margie was here, she
would ask the same thing. So that's
that's all I've got on that. Um we have
13 minutes. I I'll tell you what, just
so we can go straight to the questions.
just so you're aware what's happening
this fall in the next 90 days. There's
four more milestones. Um there's there's
plenty of other stuff happening, but
we've already um actually the first one
is something I learned about a couple
weeks ago. It's uh I don't know if
Richard is saying you're you're
partially responsible for this or you
were just one of the key speakers. um a
little bit about yeah I mean Ben Moscow
is is the lead guy really pulling it
together with the future of life
foundation and project and a few others
but um yeah it's just an attempt to
build an alternative AI stack is the way
they think about it and the ultimate
objective is to bring this to the global
AI summit happening next June uh in
Geneva Switzerland. So they want to walk
in the to the room and basically say all
you people who are like trying to create
transparency and accountability blah
blah blah for the MLMs and the big guys.
No, no, no. We are the we're building an
alternative sort of
that that's the I think this is the
initial sort of convening of these 3400
people I think are coming
and
thanks to Richard Ben invited me and I'm
like just what I need another trip
across the country but I'm going so I'm
definitely going to be there and thank
you again for that. go uh you know again
my premise is and you saw it here this
morning we are building the the trust
foundation that's needed for that so
yeah the full requirements for producer
AI well that's what that's what happens
building uh you'll show us that at the
next point [laughter]
I'm not here
>> who just decided to leave
>> I apologize I have an interview in 10
minutes and I need to
>> a little bit [clears throat]
way to make kissing [laughter]
a good excuse to go. Anyway, um actually
I said four to five. Um Bron's coming up
in just over a month. Um yeah, I know.
Uh then as I mentioned the green build
conference um and by the way that lead
the lead architect on that has agreed to
um come and give a talk to uh
decentralized trust working group um to
explain why the vision of smart
buildings
next internet identity workshop first
week of November and then two weeks
after that both ITF in LA and the SEI
summit um state endorse digital identity
in Utah uh at which they've already
shown a strong interest in showing or
[clears throat] having us give a talk on
how setting credentials will work as
personal credentials for BPA it's sort
of obvious but anyway that's all coming
Um, and then the last thing I'm going to
show you is this is a quick overview of
the talks.
>> And I I'm certain I've missed some, but
these are the ones that I know we are
involved with. Now, the ones I missed I
know are ones that um Martina is giving.
And by the way, I' I've heard
conflicting things about Christopher
Allen being here or not being here. Do
you know the truth?
>> He's not.
>> Okay. because I talked to two people
yesterday who were stunned to say, "What
do you mean? Of course, he's going to be
here. He wasn't been on all these calls
and everything." And I said, "I don't
think he's going to be here." So,
Martina, can you quickly just tell folks
when your um talks are?
>> This is somehow conflicting as well. So,
I checked this morning and I saw the
first one is about South identity and
the next 10 years. So it will be kind of
a recap whatsoD is uh what the community
achieve and what we are currently doing
and how we envision the next 10 years
the responsibilities that come with self
identity it will be on the second day
which is Wednesday at 9 a.m. in the
morning and the second one will be uh
the least worst centralized
government. Yeah, [laughter] that's the
very last day
>> which is together with Elizabeth um on
the last day on Thursday the last
session slot.
>> Oh, last session. Okay.
>> Unfortunately, I think that is also the
one that
>> No, no, no. That one's been moved. I
will be able to come to that one. They
put me on this one which I
[clears throat]
Well, anyway, I think it's the
announcement about what's going to be
happening with open wallet. So, it's
directly opposite. I saw that I was
like, I won't be able to go to that one.
Anyway, so those are the two that I
don't have listed. Um, these are the
rest of them. I highlighted the ones
that we actually submitted. Um, and uh,
this is the one that this is largely
going to be Richard. I'm just doing
Daniel and I did a very short intro.
This is the one that primarily Well, you
shoot a bunch of slides from it already.
And this is how we'll be doing the key
ring. The other ones are just ones that
we've been asked joining to speak on. So
that's
that's the
questions or thoughts or discussion
items now that we're so close to our
end.
>> There's too much at once. That's
>> I think there's so many questions that
we probably would want to stop because
it's a so many things that are possible
as soon as we get into this paradigm
like hard to complain myself to think
you know just coming from my own area of
uh domain names where you have a huge
problem of identifying people and it's
just not resolved and people have been
taken this is the new normal of not
knowing
>> which is disaster and then the whole
thing relies on domain names and people
pretend that they know what they're
dealing
that almost feels like a whole
subject that we could yeah
>> we could dive into separately which by
the way is also
>> fine we should connect
>> and uh but but that that might even be a
good topic um to bring up or or have you
give a talk to our decentralized trust
work I'll be very much interested in
this
>> okay good let's let's follow up on that
Martina Yeah,
>> that's questions in chat.
>> In chat. Okay, good. Let's uh up over on
that.
>> The entity supports TRQP. Are they a VTN
or where do they sit?
>> Or are they stuff?
>> Uh they're a VTC.
>> Yeah,
just found that one speaker. Yes, that
that would be my answer.
>> Thank you for that. Appreciate it.
Uh
yes.
Um well, we could go into in fact will
your use cases
um around hand and kind of both register
you need and potentially how you would
use VTAs.
That's another very rich subject that
might be worth um
>> Yeah.
>> Yeah. Will's Will's Will Will Will's
world would fit well.
>> Exactly.
>> Speaking of that, so also not on that
list was Daryl's um talks there at least
two that day two beta room is trust
registries
ranging from the the patterns that
repeat because it's the same pattern
every time. got a credential need to
know if it's real. um through to tech
through to other other that's all beta
room to Wednesday sorry day two
um from 9 till pretty much the end of
the day it's all trust registry stuff
I'm speaking I'm speaking at 9:00 a.m.
But it's like the whole in that room the
whole room is trust registries all day
and
>> how the trust registry fit in with the
trust network
>> the the onion diagram that Drummond
shows meaning you have a credential you
need a trust registry somewhere in the
chain you have to answer the following
who said that issuer is authoritative
and the answer can't be oh they have a
credential because if it is it turtles
all the way down
>> but isn't that the same as the trust
network like to me the trust network and
the trust registry [laughter]
>> it's an as it's an aspect of a trust
>> okay
>> trust registry
>> every trust network must have a trust
registry if you want anybody outside
>> not
registry is a trust network like if you
say a network of networks then it's a
list of
>> the trust registry
>> list of organizations which is a
registry
is what keeps a trust network honest a
trust network may not always be accurate
at point in time
>> what does Does it mean the trust network
might not be accurate?
>> So if you you could take a copy of
certain credentials, but something has
happened which means I've actually
revoked some of your credentials. And so
the trust registry's role is that the
community owner, the VTC would updated
its trust regist and said something that
Mitch is no longer uh he's been kicked
out.
>> We have different ideas going to be in
this registry. So that's a really good
day on it. I think is how I completely
it's good. We're gonna have a whole day
to discuss this. This gets to the same
question where the trust registry is the
map but if there isn't a trust registry
it's just that
>> and if my perspective has changed
because there's been some revocation or
whatever the there needs to be a
registry to be updated but if that's not
important to the community
>> yeah that's may be useless
>> where the vacation sits right to me the
network at the need to know who's in the
network Yes.
>> So if a community's been kicked out of
the network, that would be at the
verifiable trust network level. Whereas
if a individual's revocation that would
be at the community level.
>> That's right. Yes. That's right.
>> Yes. Okay.
>> Exactly.
>> It's it's at a very very high level.
It's like DNS for trust. Uh and I know
it's a it's a dangerous analogy, but it
needs to be as efficient as that. That's
>> I think I understand it correctly. Yeah.
It makes a lot of sense and I'm I'm
really looking forward to my slide, but
if if I had thought of this one, if
we're talking about what's happened last
year,
>> Darl just told me this.
>> So last year here, the question we got
about trust was literally what is a
trust registry. The question now and
Apple is Apple and France chair the task
force that I'm I'm on
it.
>> You are a co-chair of that.
>> Yeah, it's not listed. They call it
Daryl's track, but yeah. So,
um the 220, so you have Apple and France
basically saying we need global
registries to hit to understand because
they're hitting, you know, there is no
answer for the United States driver's
licenses. AMA is a partial answer.
California is not in their digital trust
service. So, you have that's in one
country, you don't have an answer. They
need one credential in one country. one
type of credential in one country, you
don't even have an answer yet. So they
need a global registry of registries, a
decentralized network of these things
and they want to understand how does it
become operational and it was in need of
funding because it's the term they use
in the GDC context was it's crushing
them right now.
>> Yeah, they were pushing this ball up the
hill, this stone up the hill about
driver's license. Get in your wallet
getting down like uh oh uh
>> oh it's starting to roll down the hill
fast. It's nice to see and grace you're
absolutely right that picture totally
depends
>> on trust registry is interoperable at
all which is why this
>> it's why this stuff
>> you know came out of out of IRA um so
>> so we got to solve these problems
together my um the optimistic view on it
is because we have a common way of doing
it because we're building this
infrastructure we're actually going to
show folks not only the role but how
those registries work and how they can
multiply Why? Um, and in the end, I
guarantee you, we're going to be I mean,
this is why when Darl was asked to
co-chair this thing with France and
Apple, I'm like, whoa, folks are
starting to pay attention. Yes. So,
anyway, we are uh hitting time and I
just want to thank all of you for taking
the time to come this afternoon and hope
that you have a fantastic You are all,
by the way, um, uh, what's the right
word for it? um delegated
>> as ambassadors um
>> first person project decentralized trust
BTI whatever the hell if you want to
carry the word
>> any and everyone that you talk to where
you're going oh that person's interested
feel free to put them in touch with any
of us um and you know we just we'll
carry this forward um John and another
word of describing delegate deputized
deputized. Perfect. [laughter]
>> You're all deputized. I would give you a
picture as soon as you have it.
>> Yes. Anyway, thank you all very much for
coming. What's that?
>> Um
um dinner. Where's dinner going to be?
>> Yes.
>> The important questions.
>> As the huggers guide would say, that's
somebody else's problem. It's a message
something who actually wants and what
time because I heard people want to pick
up the badges
>> badges
becoming available what time
>> 5:30 to 7 I think is badges
>> 5:30
we want to aim for seven then we
>> and where because this is now going to
pal expo and then back here is this
>> probably not back here it's
the phone.
>> So shall we close the session?
>> Yes.
>> Yeah, I think we should. Thank you
everyone who's with us. We really
appreciate
>> and uh
Alex
who is interested in having dinner. So
in this manner