DTGWG Human Trust Experience Task Force Meeting - 2026/09/15
Watch on YouTubeVideo summary
The meeting focused on addressing critical risks associated with data oversharing in future EU digital identity wallets by proposing a new "Trust Disclosure Agency" layer designed to enhance user agency. Drawing upon fifteen years of research from ETH Zurich, the team argued that users often lack full rationality regarding data sharing due to bounded rationality and heuristics, necessitating a shift from one-off interactions to an iterative trust game model. This approach utilizes mathematical models demonstrating that even a 33% discount factor on future value is sufficient to incentivize cooperation, distinguishing itself from the Prisoner's Dilemma by incorporating reputation effects and forgiveness mechanisms that allow users to expand or reduce data sharing as trust evolves. To mitigate potential new risks, the group decided to implement this system through rule-based, mechanistic logic rather than relying on AI inference, ensuring safety while validating interaction patterns across diverse cultural contexts.
Significant progress was also made in refining persona management and the overall user journey, clarifying that different "worlds" such as work, life, and play are not hierarchical over applications but rather represent contexts where various personas interact with financial identity. The team agreed to simplify the onboarding process by starting with an invitation flow instead of requiring users to manually create profiles upfront, utilizing derived attributes like GitHub connections or uploaded CVs to curate faces throughout the user's journey. While acknowledging that heavy lifting occurs beneath the user experience layer via Trust Tasks allowing for diverse front-end designs, the discussion highlighted concerns regarding data minimization under GDPR; Glenn emphasized that agents should present state information without storing rich profiles, and interfaces could be adapted, such as using audio, to serve different user groups effectively.
As the session concluded, attention turned to understanding kernel developer culture through a proposed ethnographic study for the upcoming Linux Plumbers Conference scheduled around week 12. The team recognized the need to return to original requirements to clearly define user personas, entry points, and necessary explanations, despite having existing perspectives and prior work. Margie was specifically tasked with leading UI development given her expertise, while action items were established to obtain specific advice and deadlines from Glenn and Jeff, which Nikki will follow up on asynchronously. The group adjourned the meeting with clear plans to reconvene at the next working group call to continue advancing these foundational trust and identity initiatives.
Read the full video transcript
Hello, Nikki.
>> Oh, hi Margie. How are you?
>> Good. How are you doing?
>> Yeah, all good, thanks. I'm just trying
to uh log into the wiki because I I
cleared all my cookies a little while
ago. So, I'll be straight back as soon
as I'm logged in.
Okay.
Did you have a nice break?
>> Yeah, I had a very nice break. It's
almost was too I mean it feels like it
was such a break because it was so long
that [laughter] I'm I'm having re-entry
problems.
>> Yeah, [laughter]
re-entry problems.
>> Stay at home uh camping week.
>> Yeah. No, it was good. It was uh it was
restful and a change.
>> Obviously, not as much as usual. It
wasn't the kind complete detox that we
normally have, but it was it was really
good to
just uh rest my brain for a little
while.
>> That's good. So, you need we need to
recharge
especially especially this season.
>> I think it's it's it's space. It's about
space and just
letting in a bit of light and air and
perspective. [laughter]
Yeah, we took a hike in um we took a
really challenging hike that my kids uh
dreamed up in um and wow that was that
was both space and effort and endurance.
It was crazy about killed us.
Where did you
>> hike?
>> We went to the Doommites and did trail
called the Alta Villa one and it's just
>> Wow.
>> straight uphill for a lot of it. It was
really, really hard.
>> Well, congratulations on completing the
hike and returning.
>> Thank you. Yes.
felt like I just needed to lay down for
a week after that [laughter]
>> in a darkened room. Yeah,
>> exactly. Or like in I went straight to
uh swimming like swimming in the ocean
and that was my remedy.
>> Hi others.
>> Hello.
>> Hi.
Morning.
Okay. So,
we'll just uh do the normal antitrust
policy notice.
Um,
[clears throat]
so just be mindful of antitrust and
competition law. Um, and it's important
that we adhere to the agenda
and only kind of participate if we're
members of the relevant organizations.
So I don't think there's anyone new here
today. So we'll scoot through that bit.
Uh, just quickly whiz through the agenda
and then we'll come back to general
updates.
So, um Daniel will introduce uh yet
another enormous and uh rich piece of
work um for us to have a think about um
and then provide an update on trustlets
and the best pract practice repository
and then we'll take a look at the
uh persona management that Glenn asked
us to take a look at uh last week which
is in this GitHub discussion
um
and uh
some updates. So I'll I'll leave that uh
um so that uh I can just uh do my normal
kind of guiding the discussion
[clears throat] to come to some outcomes
and then we'll wrap up. Is there
anything else that anyone would like to
add to the agenda or change on the
agenda?
>> Only that I'm unfortunately have to
leave 10 minutes earlier to catch a
train. So, sorry about that already.
[laughter]
>> No worries. Um, well, your stuff's up
front in the discussion, so that's good.
Uh, great. Any general updates from
folks.
Okay.
Uh over to you Daniel. Do you want to
share screens? Yes. Or
>> Yes, please if possible. And
>> of course,
>> I really tried to make that short.
Although I could talk for hours about
it. Um, let me quickly share the right
thing.
Yeah.
So,
uh, I hope you can Can you see uh the
screen
I'm sharing?
>> Yeah,
>> I guess that works. Good.
[clears throat] So uh what what I want
to do is just to introduce something
that is very close to my heart and has
been a topic of research for at least
the last 15 years. And and it it happens
now that I had this discussion with this
other researcher of the GDC uh which
um realized that they have been looking
from a security perspective on a similar
topic uh and the topic that is very
relevant and it basically means now
given the fact that everyone will have a
wallet very soon. Um so what is actually
missing and there are a lot of pieces
missing and I really recommend you to uh
look at their paper just released in
June
u that uh assesses uh this uh risk of
oversharing uh in the uh future EU
digital identity wallet uh and they have
a an empirical analysis on how that's
going to happen and what is needed and
the interesting part is what is needed
and that's actually what I'm also been
looking into for years and this is this
layer for agency. So a little bit
something that helps the user also to uh
make this disclosures and not just press
consent because yet another consent
button is not digital agency and doesn't
really help anyone because it's more or
less the status quo just in an automated
way. So the VTA runs into a risk just to
be a delegated constant machine which is
not what we actually need to design
because it doesn't solve the real issue.
And the real issue and that's for for
many a little bit hard to understand but
quite simple is that we are not really
rational when it comes up to sharing
data. So we have this horistic behavior.
We have these biases and we we are
bounded in our rationality and secondly
we our mental model will be completely
overwhelmed uh with selective disclosure
and the technology behind so as the chop
no one wants to know what it is and and
also shouldn't because we wouldn't
understand our mental model doesn't work
like that. So why not think of a layer
in between that uses uh all available
information and maybe a little bit more
to actually support the user in this
process. And I'm now sharing also with
you already in in our HDX page here uh
the uh the paper more or less. It's not
an official paper. It's Rodri a concept
paper that um looks uh at both findings
from my research and also from the
research of this ETH team and derives
actually then a few blocks of
requirements that we should consider and
I know it's it's a big topic it's
probably not priority number one and
it's not nearly close to priorit
prioritized compared to the pumpers
conference but may if you opt to that if
if we have a little bit of capac
capacity, we really should use the
opportunity to uh to to level up this
VTA that we're planning to build with
this kind of capability. Uh that would
then really help us um in supporting I
guess the user. So I I won't really want
to go very quickly through the basic
points so that you hopefully see what I
mean. So uh we are talking about a uh a
layer and I called it now it's all under
development but I would find a good name
is this trust of disclosure agency layer
because it's exactly that. So our our
support layer should uh enforce an or
enable agency and it needs to be trust
aware because this is based on research
for uh under in environments of low
trust. Uh and that is basically what
changes the game and I will come to
that. That's a very important thing.
It's not only a nice sentence. It's
important that we talk about games here.
So the evidence is quite sure now. We
all know about the privacy paradox. We
all know about the data collection
dilemma that companies want and also
need to at some point collect data. But
we also need to minimize data from the
legal perspective. So there is a huge uh
warfield there and there are also
numbers. So this uh effect of
oversharing is going to happen in a
status quo with these wallets. So that's
what uh these research colleagues try to
find out in experiments and with mockups
and in interaction with users. Uh and
they found that this number is very high
as we assumed from the privacy paradox.
They think that about 20% would even
provide an ID, an official ID to a
website, a news website. And that is
classical oversharing because no one
should have to do that. But they would.
And they also found out that with this
kind of notching layer, we can reduce
this oversharing and that by by quite a
high factor. And now my part of research
is is rather from the information as
symmetry perspective and a little bit of
game theory. And the good news is that
uh if you look at analytical model for
something like that so mathematical
model then the uh the effect that we
need to introduce doesn't need to be
really big but the effect is clear. We
need to have something in there that
enables cooperation or supports
cooperation. And this is then being done
by adding a certain value for future
interactions. So we we should stop
looking it at a one-off game. It should
be uh it is definitely an iterative
game. You will not share data once. you
will will maybe share data in different
iterations a different amount and you
will maybe change the view of the world.
So once you have seen that a partner is
not cooperating you shouldn't share
anymore. So you have to exit the game
and cooperation as I said of course is
enforced if uh the future value of the
interaction is there and you might not
think ah it must be huge value so a re a
huge discounted cash flow like for
companies going public [clears throat]
and that's not true because the model
already shows that a discounts factor of
one/ird meaning 0.33 or 33%
is already enough to motivate everyone
to cooperate also the future. So imagine
the discount factors like an interest
rate. So you can discount future profits
by 33%.
That's a huge interest rate. You you
barely look at future revenues, but it's
still worth cooperating. And that is a
good finding. So these models uh or or
what we do has a great chance to
succeed. I will show you a little bit
more how we get to these numbers. But
then now first what is it? So we have
this identity and trust infrastructure
of course um this will be all these kind
of wallets uh and and also together with
trust registry. So the the whole VTI
structure probably and the human being
of course that's why we call it the
first person project and this VTA is now
the key to for keys credential and
proof. So it's taking away the work that
human beings should do. It's a technical
thing right now for key management and
so on. And all it also decides more or
less uh how or to share data but now the
missing part is this layer this decision
layer that supports the user in making
decision how much to share and how to
behave in a future interactions
and this is a bit the mind shift. So
it's a dynamic component
and so there are a lot of capabilities
that we define now some of them origin
actually from the paper of the
colleagues but I have also my own and
together I think the picture is quite
nice because they also mentioned the
missing part exactly that that we can
cover that we have identified this these
are here for example the native
principles so it's quite a list of
capabilities but the good is we can
derive requirements from there. It's
still a big thing to do and not
everything is clear how to do it but
there are a lot of good ideas around and
we can operationalize this uh very well
into code I guess but it takes time but
I guess it's worth the effort. So
basically it's a huge important to
understand the situation. So our VTA
needs to be able to reason about the
situation otherwise it doesn't make
sense. It must observe the request. It
must know the principle and with the
principle I mean the human being the one
that the agent is care caring about. It
needs also to verify the rying party as
good as it can evaluate commitments and
also understand and explanation and
explain what what's happening and then
the decision part. So there are
strategies. So the we need to be able to
assess a minimal best situation where we
already know mathematically where it is
about. So this can also be programmable.
Uh the least revealing proof. Um then
select the strategy state. That's a very
good one I guess because it's about
strategy. It's not one strategy I will
show you. There are more parts of
strategies that you need to apply to
play the game and so on. So there is of
course more and the interesting part is
the feedback loop as usual. So if you
can learn from an interaction and adapt
the state of your world afterwards you
can make this system even better and in
the end or in the middle even here it's
still the human that decides. So I for
the sake of time I will skip a little
bit the game theoretical
things but game theory is a wonderful
thing to u build mathematical models and
illustrate the the mechanisms of the
game and
maybe there is one important thing to
understand. We we always tend to think
about the prisoners dilemma when it is
about data and this is it's just also a
bias. If you look what uh Mr. Trump has
been posting yesterday there is has been
a an ice post about this discussion
about AI and whether it's a a threat for
humanity and everything he can think
about is that they only need one
guidance guardrail and that is an
intelligent president and of course they
have that so we are all fine and it also
mentions that he needs to be ahead of
the Chinese and so on the usual game and
and unfort it's also a position that
Palanteer shows
that's easy it's understandable because
if you have adversaries you have to move
but you are playing the wrong game
you're thinking of the prisoners dilemma
and this is uh where uh everyone doesn't
know how the other one reacts and you
move uh in the same time uh and the the
bad thing with the prisoners dilemma
coming from the inmates if you confess
or get out and so on is that it will not
lead to a good uh utility. So a good
outcome because there is the Nash
equilibrium as we all know and that will
force us to a superior result because in
the end of a prison dilemma no one
cooperates and we are missing the
opportunity of everything. But the thing
that maybe Trump
makes a mistake is it's not a prisoner's
dilemma because our game is a different
one and it's a trust game and the trust
game is also very popular in game
theater for years. The difference is
that we have the iterations we have
vulnerability once data is shared you
cannot take it back it's gone. So this
damage is there there is reputation and
so on. So we have a lot of more signals
than Trump is thinking about. So it's
not about the Chinese are bad. It's not
the one signal. There is a lot of social
signals in there that we need to use in
a trust game. And if you model that as a
trust game and that's here only an
abstraction, then you will find out how
these payoff matrixes can really look
like. And the good thing is also you can
derive uh equations and see how you can
steer the system. And you can't steer
the system. You can lower a GB cheer the
extraction gain. You can raise Q when Q
is uh the uh the observability maybe or
the audit throughist. You can raise
different uh amounts or also different I
say levers in the equation also alpha
for example and that is the noise. There
is always noise. You have to account for
that. But the worst thing to do is just
to take noise and then exit or uh or
take that too seriously. You have also
to be able to have something like
forgiveness in a real play in a trust
game and that will increase your
expected utility for both sides
dramatically.
So the last picture here, there's not
one strategy when you start the game. uh
you don't just share everything you need
but you have the opportunity to share
just something and hold you have the
opportunity to expand. So once you have
more trust in the relying party, you can
share maybe a little bit more for the
benefit of both. You have or need to be
able to reduce once you see that the
likelihood or the risk to for a defect
from the other party is too big or also
if if if just the uh the the system
tries to get information that is not
accurate. And you also need to be able
to recover or to forgive so that you can
expand again in order to reach the
utility maximum. And these are the just
the mathematical equations for all these
strategies. And they're pretty easy look
look very bad but actually they're
gentle because we know that the
determinants we know these what we have
to change. we only need to find a way
how to programmatically steer and change
them. But with these uh mathematical
model and the right mindset and the
right capabilities
in our VTA, we might be even able to
implement such a system and that would
be something really new where I think we
could make really a difference then. So
that's it in a nutshell.
What do you think?
>> Well, this is a a very short section.
Um, [clears throat]
sort of trailblazing. It's like an
advert for a longer session. I've got a
list of stuff I know that I uh from
reading the document and uh
>> kind of connections and
um interesting factors. I I you know
it's it's great work I guess for this
group the the human
trust experience task force
uh what would you imagine the
deliverable might be that we would
produce
um or is is there
recommend you know what I guess what are
what are you looking for from this group
would be my
>> primary question but it is
uh you know it picks up on
the key human problems. Um
there are many other factors involved in
it. Um [clears throat]
but I you know I think we could give it
a go. the the VTA. I noticed you said
that you'd been working on it for a
number of years and I wondered what
you know when was that kind of light
bulb moment of aha it's the VTA that can
enable this stuff to happen? [laughter]
>> Yes indeed. So because it has always
been a very formal uh kind of work
because there there was never really a
chance to implement that because you
never have critical masses. You you can
only do what actually the colleagues did
and this is experiments but experiments
are not interesting I would say because
of all these this round bounded
rationality issues and also the the
privacy part. So people will will not
tell you the truth if he asked him
actually. So that's why it was very
theoretical. uh but I now see the
opportunity that something can actually
be built or it should now actually be
built and that's why it's it it has some
new energy I would say and it's also the
outcome of of the study they did is that
that there is really something unsure
and unresolved before also the AU wallet
goes out because that's that's a real
risk and also the Switzerland has raised
this risk
that that we now have then an
infrastructure and wallets but we have
not solved the problem of oversharing
yet. So
>> yeah I mean it is an actual issue. Yeah.
When we wrote the harms paper, one of
the key risks that we identified was
um like oversharing on the consumer side
but over asking and over verification
um which is where the requirement to
verify the verifier comes from the
mutual authentication verification
and that's part one of the kind core
driving requirements behind the trust um
registry query protocol and the whole
trust registry infrastructure.
>> Um
>> any anyone else got any thoughts or
comments for for Daniel? And
is this something that we'd like to
dedicate more time in a future
task force meeting to discuss?
Margie
Yeah, I think we definitely should
discuss it more. Um, I have two
uh thoughts. One is well um one is that
the
the diagram um O2 one loop 15
capabilities. I think that would really
benefit from
walking through a real world scenario.
you know, just making that very concrete
as like a yeah,
>> in a story effectively that that would
make it maybe more digestible. I think I
think I got it, but it would be helpful.
>> There see something similar like that in
in the the paper. It's only it's 50
pages, so [laughter] don't you don't
have to read everything, but there is
kind of a scenario in there as well.
Yeah. To make it a bit understandable.
Yeah.
>> Okay. So maybe that I mean it could be
that that's a deliverable from this. Our
first deliverable is that it's kind of
uh storyboard
>> the the thing out so it's everybody is
sure they understand what what is
happening. And then the second thought
um
uh if you go down to 04 well actually if
you 03 and 04 um
one question is is this purely
mechanist or are these formulas
mechanistic or are they
AI inference driven because I'm asking
because
um if they're purely mechanistic. That's
in my opinion that's a good answer
because you're not introducing um the
the trust variables around the AI models
themselves into this thing that's
resolving trust, right?
>> Um but yeah, so I um to me I think you
would if we were to pursue this,
it would seem to me to make more sense
to pursue it as a mechanistic
thing. I don't know if anyone else does.
>> No, I I think that is a very good point
because what you say is is a real risk.
So if you if you automate it too much or
put own model risk in it, then we might
make it even worse than it is or
introduce a new weakness that we also
have to mitigate and and you're
absolutely right. We we we don't we
shouldn't do that because there is a I
think no need for it. uh because we can
make that rule based rather uh so and
and and secondly the risk is just too
high and it doesn't make sense. Yes. So,
but that that's a very a good point to
pick up, but it would make it even
easier to do I guess because there there
is no AI reasoning behind except maybe
the evaluation or understand the
counterpart the lying party because at
at some point we need to find out how
much evidence we have. What's the
assurance level? How do we look at this
alpha? The alpha is the noise. How clear
are trust signals? Can we use them or
should we not use them? So this is where
we have kind of a classification but I
think we can make or should make that
rule based. Yeah. Uh but I see that
actually possible because yeah it's it's
it's the the main question is rather
where do we get the signals from and how
do we read the signals and that's then a
little bit more complicated but also the
good thing is we also have answers here
because people have thought of this
situation. We should do that. But we
should also know how confidence we are
about the alpha and the signals because
the highest the biggest risk is also for
example to show a
a a big uh I say proof of evidence that
someone needs this and this and these
parts of data because the longer and the
more explicit this proof is be
cryptographic or not but if the customer
sees it he tends to believe it even the
content is still wrong. So, um this is a
difficult thing to do. Yeah.
>> But not too much AI. Yeah.
>> Great.
So, uh Lynn asks, "Is this just an EU
wallet or wallets in general issue?"
I I think it's it's both. is just the EU
ecosystem is being bootstrapped by the
national governments,
>> right? Yes. Well, it it it is a natural
uh thing unless someone else loves it
already in a wallet, but I don't see
someone really care about it because
they they are also missing this VTA ID,
I guess. So, something that actually has
some capacity to work for you or to
assist the user and most wallets are
hardly storage, aren't they? Yeah. So
they would not care about it. And and
the EU and Switzerland, they only look
at that now because they set the
timeline. So they want to be ready end
of year or at least the EU wallet will
be ready end of year. Uh so they feel
already the pressure by knowing they
have unsolved issues.
But I think it's a general issue. Yeah.
But that's also a good thing for us
because otherwise we wouldn't have a
mandate.
Great.
>> Yeah.
>> Okay. So, do you want to give us a quick
update on trustlets if there's any
>> and on the best practice repository?
>> I can. Yes. And we touch for it again.
So, there is not too much of an update.
I have further tried to uh stress this
pipeline a little bit and train it a
little bit more and there is another
video available for you to look at if
you want. So there is now one uh I think
also about the trust graph as such and
this second reader has now been able to
be produced in in a short iterations so
it improves but I'm not there yet and of
course alignment with trust bites uh is
not yet done and it is kind of a little
bit of a different world yet but we need
to of course still do that or or find a
way how we can have the a combined maybe
approach at one point or or just not to
to use such a pipeline. I don't know. Uh
and then the next thing is also maybe
the the the graphical uh design
guidelines
are of course very important. So once we
have a clear picture on on how our
communication should look like what the
uh not only color and fonts but uh also
what the messages should be what the
tone should be then we can of course
fine-tune such a pipeline and see
whether we can produce uh good quality
with a little bit less effort or just go
to the created approach back which is
definitely more quality but also much
for uh effort properly.
>> Fantastic. Well, you're a one-man task
force. [laughter]
>> Yes.
>> It's like
>> so just for the byite-size trust. So, we
just met on Monday and we're going to
meet again in two weeks. So if you want
to join for that then we can
>> have the and and the other thing that we
talked about that uh um at by size trust
is that we
>> didn't want to start making videos until
and I think this is a good idea until
there's a version 1.0 no release of
decentralized trust graph otherwise
we're constantly chasing a
an everchanging spec because I I've seen
lots of changes in the specs
>> uh the names of things what parts they
need and so on.
So so right now by size trust is working
on making uh um because there is a 1.0
upcoming release of TSP. So, we're going
to work on that first.
>> Now, there's valid point, of course.
Mhm.
Okay. So, the persona management stuff.
Um,
here's the discussion.
Open a new tab. Here we go. So, I don't
know how many of you had a chance to
look at this. What Glenn's done is
provide a series of screens
that starts with your attributes
and kind of collates them
based on the discussion we had last week
into these worlds and faces.
Um,
and then
how you manage those worlds and faces
against contexts.
Um,
how you add an attribute,
how you add a world
and a list view.
So, Margie, um I think you've uh added
some comments.
Um do you want to
kind of step through your stuff?
Editing your face. Sorry.
>> Yeah. Sorry. Um well, I just I just
wanted to I I may be behind because you
guys maybe have already discussed this.
So I was just trying to understand
the relationship between the concept you
know elements of the conceptual model.
So the first comment was just about um
whether context is a subset of world. So
if if I have a world that is banking
and a context which is
mortgage and another context which is uh
philanthropy or something or you know is
is that how it works that I have a a
larger
the money bucket has different content I
I don't know it it seems like that is
what he's saying here and I think I
concluded that was.
>> So I think there was a bit of a
misunderstanding about that because
he's kind of inserted a layer which is
these worlds
and really the kind of uh work life play
model has money at the center. It's not
a separate persona. It's just that your
work life and play persona interact
always with money and that's where you
know the rubber hits the road basically.
Um and I think really contexts are
applications. They're places you're
using this. So um that there's no
hierarchy
um between worlds and faces and
contexts.
Um, you can have a face. My
understanding is you can have a face
that exists in multiple worlds.
Um, and actually my follow on comments
were just take it out. Either you can
use it to bootstrap
to help people get thinking about it. Oh
yeah, I've got a different email address
for work versus home or something like
that. But um
uh I I'm not convinced. There's
certainly no hierarchy and you could
take worlds out and not lose anything.
He only put it in after a comment from
us during the last uh meeting.
>> Okay, that's I have to get my head
around there's no hierarchy then. Um,
but I like that better and I like
eliminating
a component if possible to simplify.
>> Yeah.
>> I mean, the human side of this is
like it's a natural human thing to have
multiple persona
>> and or faces and and that's actually
grounded in research. This idea of
faces.
>> Yeah.
>> You know, when you introduce yourself to
someone at a party, it depends on the
context, doesn't it? Is it a work party
or [snorts] you know something at a
little festival or an after you know
there
how we introduce ourselves to each other
depends on where we are and what we're
doing.
>> Yeah.
>> Mhm.
>> So you might be a chess champion but
that's not what you lead with
when you're on a date maybe or or when
you're applying for a job. you know, you
you lead with your qualifications for
the job or
um you lead with a question about your
date in a dating environment.
But this idea that I have multiple
persona and that's perfectly healthy
even opposing persona
um or identities
um and that is a normal identity
pathology.
Go ahead, Margie.
>> I'm wondering if
it all of this struck me as pretty
abstract like of of course this is con
it's it's conceptually rigorous, right?
But it's not grounded in a
and maybe this is dangerous territory.
it's not grounded in a metaphor that is
already
available in people's lives. So, you
just gave a really great example of, you
know, you you introduce yourself um
according to the context that you're um
meeting somebody in. And we had been I
mean it's getting into the R cards
thing. car like a a business card as a
metaphor
I think is helpful because it's or a
baseball card or you know something that
is like um um a nugget tidized set of
descriptors
that are relevant to a particular
context and that you have as many of
them as you need for the complicated
life you lead or the uncomplicated life
you lead. um including
um
you know a sud sud I hate to say these
words pseudonmous
uh card where which is you know
basically when you want to be entirely
um
you know you want to show up but you
don't want to share anything.
I don't know. I'm just wondering if if
we could look at it through look at this
the set of screens through a
metaphorical lens to see how if we could
make it more understandable or simpler
>> Daniel go ahead
Yeah. Yeah. I know. I I also see these
points and I agree. I find this view of
the these worlds um
quite good because it helps maybe a the
user to articulate this different
personas. Also, I see maybe the the
difference to our cards because with the
worlds, it's it seems like we then
reduce it to only a few perspectives
whereas our cards probably can have
more, but maybe less is also better. And
and and also in this concept also with
context, I see already a lot of things
that I've been talking about before that
that Glenn here needs to build and
especially the context. it's quite
difficult to uh to build and you
probably cannot ask the user what the
cont context is. So it's something
derived as we talked. So maybe the agent
that helps to define the suitable
context and the right strategy and
compare it to these personas or pictures
or worlds. Um but uh I think the we
we're on a a good good track there and
it certainly helps the the users to
articulate these different worlds and
this then again informs the profile that
my agent would need to have or he needs
to know a little bit about his
principle. So know the principle can be
very well informed by looking at these
different worldviews.
So I take it as a opportunity that also
supports my model although it looks
still complicated and maybe can be made
a bit easier.
Yeah, I had um [clears throat]
a few comments also.
Uh
so I um I agree with you Margie that
we're kind of starting at the wrong end
cuz that's not naturally how we
introduce ourselves by thinking of all
the attributes we could share. And so
I've suggested a few things and um
so I'll just step you through that and
see what you guys think. So I first of
all I clarifi I clarified what my
assumptions were looking at these
screens.
Um, so my assumption is that most users
get to this series of screens based on
an invitation to join a VTC
and only a small subset of users would
need to set up a VTA in order to create
a VTC.
Um and then my second assumption is that
for the initial implementation these
users would be highly skilled developers
and software engineers.
Um
I I I don't know what you think about
how valid those
um oh by hi hi and bye Kevin. [laughter]
Um
so I I just kind of started with uh
those two assumptions. So I just
clarified this point on on worlds
because um I mean this is a model. Go
ahead Margie.
>> Oh no, you finish. I just
>> Yeah. So it's a model I've been using
with clients for like getting on for 20
years when it comes to identity that we
all have these kind of three core
personas. And if you think about stuff
and and money is at the center. So
they're not different worlds. they're
different faces
um different ways of presenting
ourselves and not obviously you might
have multiple work profiles
you know for example I you know I'm a
gig worker basically and so I've got
like a million and one email addresses
and diaries and sometimes I present
myself as Nikki and sometimes it's uh
something else um
uh so it's just a way of giving people a
starting point, a way into it. Um,
and I would also I'd start with the
context.
Um, and I I'm not sure it's that
difficult to
create your context. It's part of
discovery in a sense because it's just
the applications where you're using this
stuff.
Um, I'd also just, you know, we've all
designed sign up experiences,
um, or signed up ourselves for something
and the more stuff we've got to type and
think about, even if it is asking
questions about us, the less likely we
are to complete the process. So you
could kind of um use derived attributes
for example connect your GitHub profile
or upload a CV.
Uh the attributes could be derived from
that and then you can just kind of cross
check them and add in anything else that
you think is relevant.
Also bearing in mind that the
applications themselves
will have attribute requirements like
you're a human for example.
Um
and I think also all these attributes
would
have degrees of assurance. Um you might
be able to verify some attributes like
I'm an EU citizen or
um and and within the decentralized
trust graph model and the kernel
requirements they have this vouching
double vouching in phase four. Um
uh so that that needs to exist alongside
the self assertion. Um and then
you know the the screens are just I I'm
no UX designer but everyone gets
cognitive overload and they're just a
little bit too full. Um, so I gave a a
prompt to Claude Code
and um, you know, it it it's just an
illustration of how you could turn it
round and have more of a journey rather
than just a whoa, I've got worlds, I've
got faces, I've got contexts, I've got
attributes.
What's the point? Why should I spend
time on this? Um, so I imagine you'd
have an invitation that might arrive in
your mobile phone wallet. You open it,
it takes you into kind of your context,
which are your communities essentially
as far as I can understand.
Um,
and you can see uh the kernel invitation
there.
It asks you for certain details.
you can upload your CV or connect gear
or GitHub and it it it draws out some of
those details. Obviously, they won't
need their GPG
key. That's a the whole point of
decentralized trust graph is my
understanding is to replace that.
Um and then they they go on to choose
what they want to share which is
curating their face. They could change
the name of it. they can select what
what's seen, what isn't seen
um
and then
um
they end up with their face and they
they request the vouching. So,
and then you can just this is kind of an
optional you could you can imagine how
you could go into the sort of gardening
exercise curating your faces seeing the
communities they're accepted in. So, um
and my I guess my key comments are make
it a journey. Let's understand who it's
for. Um, and by the way, my prompt to
Claude was that it was a developer, but
they were quite a junior person. They
weren't and English was not their first
language.
So, just clearing up a few of the
screens and simplifying things. Right,
Margie? Then, Daniel.
>> Yeah, I just the one com I love these
all these assumptions. I think they're
the great a great set to start with and
I agree that the most common
uh use case is really that you're going
to be invited which which I think is the
way to start that journey as you've as
you've shown here. Um
I um when we were doing that the user
journey before though we had we had
started with the person whose job it was
to create the VT the VTC from scratch.
So I do think we have to
>> you know we do have to probably tackle
that as well but it's not the dominant
use case as you're as you're mentioning.
Yeah, I mean actually as part of the
prompt I gave them your user flows
Margie and said we're starting at the
invitation bit here.
So I I did build on the work the
extensive work that you've already done.
Um but as I say I'm not a UX designer.
I've just like got years in the trenches
with these kind of products and I know
that it it it should be the the
complexity should be abstracted
completely. It's just an enabler and
what they want to do is be able to do
their jobs with the kernel code. They're
also a very special user group. a really
difficult and special user group were
difficult for me because like I'm not a
developer. So I I look at those screens
and I think woo
where do I start with this lot? Um but
it might be the right thing for
developers. They might want a little bit
more
uh detail.
Daniel.
>> Yeah. Yes. Yes. before I have to leave
only what I I like the the idea
absolutely because I also think it's not
very likely that someone takes a lot of
time to just build these potential faces
just to have them takes too much effort
probably and people don't see the reason
why and then to flip it around is
natural idea and also this data
extraction proposition is very good the
only question I have here is what is our
position regarding data minimization so
from GDPR point of you because it's
actually also something we should not do
just to make or build out these rich
profiles because some of them might not
even be needed but we then still
>> kind of built this data and collect it
and make us ourselves vulnerable but
yeah it's open question
>> but that's the whole point of the VTA
isn't it and the selective disclosure
and the zero knowledge proofs
>> also Glenn
gave me some really important
information that I need to pass on to
you all. So,
uh
he said
one thing I haven't explained very well
is that we've designed the VTI stack on
top of trust tasks which means the UX is
actually a thin shim on top of on on top
on top of it. So that makes it very easy
for any UX designer to create their own
version of the UX.
>> And
um he's got a bit of a a vision of us
running designathons. I call them design
jams, but um and there are many
different UXs because different people,
cultures, generations treat UX so
differently.
>> Let's encourage people to build their
beautiful front ends that work for them.
all the heavy lifting is done underneath
the UX over trust task which is what
guarantees the safety aspect.
Um
he then went on to point at this article
let me
copy
that article. Can you see this?
The agent is the state. And basically
what this is saying is it's presented on
the screen and then it's discarded.
You're not storing it. You're not
building these rich profiles and um it's
exchanged in the interaction which which
is what the trust tasks you know build
up to. Um but it can be presented in any
way. It could be audio for example, you
know, and for many user groups an audio
and um verbal interface is ideal,
you know.
Um reading and and and navigating
screens and and and so forth is more
difficult. So, let me uh put this in the
chat
for you guys.
Uh, Margie.
>> Yeah, I it's I
um I have to think about it, but I think
I might slightly disagree with Glenn
because
um an example of
um people will build different
interfaces. Um we have seen that over
the history of the web. People have
built every conceivable form of a
website. Um, and they're not all equally
uh delightful, usable, um,
I don't know, uh, understandable.
And so I feel like what this group
should be doing is to
um distill out the the critical mental
models like maybe not be prescriptive
about
UI the UI layer but be
decisive
confident about the patterns that any UI
layer might have to follow in order to
promote human comprehension and utility.
Good. Yeah. So, in I characterize these
as interaction patterns and I think you
can be quite prescriptive about them.
Um, I just I I'm always a little bit
wary
in saying what works for human
comprehension because it's invariably
with the best will in the world is what
works for us
from our perspective in terms of human
comprehension. I mean the the the
construct of the wallet itself is
western you know north northern
hemisphere.
>> You know uh stores of value and status
in other
types of communities include things like
jewelry or ritual scarring and of course
clothing. And you know my my wealth and
status is projected through the size
size of my cattle herd and which grazing
land you know so [clears throat]
it's always
all we can do is
the best
from our researchbacked
and evidencebacked perspective.
Mhm.
>> Um
and and then provide hooks and en ensure
counter
um in ensure critical friends in other
types of community. I think that that's
the best we can do in in our situation.
Um so I'm not saying you're wrong. I'm
just saying that we I'm always ultra
cautious about saying this is what works
for humans because invariably we can
only speak for a small group of humans
or you know a group of humans.
I wonder like in in a normal product
development process, you would
you would come to patterns and you would
um you know prototype the sequences that
embody the patterns and then you would
show them to uh different audiences to
to
uh confirm or to validate or invalidate
whether things made sense, what does or
doesn't make sense to people. Um, and
ideally you do it, you would do it in
more than one cultural context or as
many cultural contexts as you could
uh feasibly
um do the same kind of test.
Um
although that's not Carly Heida
commenting on that
>> in
>> yeah I think the the challenge here is
well the opportunity with this that
Glenn's given us is it's a real world
application isn't it so we don't have to
worry to we need to understand the
culture of kernel developers so I I
don't know who's going to the plumbers
conference But a little ethnographic
study would be brilliant. [laughter]
Uh, okay. We're one minute over time.
Thank you all very much for your
contributions. I think next week we
perhaps need to continue to work on this
and Margie maybe if you can
lead us on on you're the UI expert. Is
that
suitable?
>> So, what are what are we trying to get
to for Glenn and by when?
>> Um, he wants advice on the UI for this
persona
and the Linux plumbers conference is
12 or something.
>> Yeah. Okay. So basically we we want to
do in um iterations on maybe the
expiration done.
>> Yeah. And I think uh so we can text him
asynchronously to kind of be a bit more
specific about what he wants from us. Um
but I think it's just some advice. But
I, you know, when I was looking at it, I
I've obviously got my perspectives, but
I kept going back to the work we'd
already started
and
the requirement set that we received in
the first place and just thinking, yeah,
we need to go back to that. I need to
design who who's using this, where have
they come from, how do they land on this
screen, you know? um and and thinking
about the explanation that's needed that
we'd spent some time discussing and so
forth. So,
>> I think that work is it's a good
opportunity to kind of string it
together. Um but I agree we need more
specifics from Glenn and Jeff as to what
they want by when. Um so I'll take that
as an action.
>> Okay, great.
Thank you, Nikki.
>> Yeah, take care, guys. Have a good uh
week and see hopefully see you guys
tomorrow at the uh working group call.
Okay, bye.