diff --git a/statement.md b/statement.md index 5462e6b..0f5a2e6 100644 --- a/statement.md +++ b/statement.md @@ -1,6 +1,7 @@ # Account verification, for everyone, without IDs *A statement and roadmap for democratic verification. Draft for community feedback.* +Co-authors: gui.do, emily.space, sherif.eurosky.social ## What we believe @@ -17,7 +18,7 @@ This proposal is formed around six principles: 1. **Verification is for everyone.** Everyone should be able to verify their account. Practical capacity will require prioritisation, but the direction should be towards universal access over time – not a permanent inner circle. 2. **Identity, not endorsement.** A mark confirms who an account belongs to. It is not a quality, popularity, or alignment signal, and apps that display it should make that distinction explicit. 3. **Issuer always named.** Verification claims carry cryptographic issuer attribution at the protocol level. Apps must surface it. No generic "verified" badge without naming the verifier and what they are attesting. If a mark composes multiple attestations, its components must remain inspectable. Without this, "verified" becomes a brand others can launder. -4. **Free and ID-free.** A verification mark on this network must not encode, reference, or be conditional on a government-issued identifier, and no labeler, AppView, or app should publish a mark whose issuance required the user to present government ID to the operator of this network. The mark itself is the line: it answers "who does this account belong to," and that question must always be answerable without fees and without government ID. Regulated claims that legitimately need government evidence (age, banking, professional licensure) are a separate class. They may be proved to a service outside this network’s verification surface and surfaced on this network as distinct attribute attestations, but never folded into the verification mark. +4. **Free and ID-free.** A verification mark on this network must not encode, reference, or be conditional on a government-issued identifier, and no labeller, AppView, or app should publish a mark whose issuance required the user to present government ID to the operator of this network. The mark itself is the line: it answers "who does this account belong to," and that question must always be answerable without fees and without government ID. Regulated claims that legitimately need government evidence (age, banking, professional licensure) are a separate class. They may be proved to a service outside this network’s verification surface and surfaced on this network as distinct attribute attestations, but never folded into the verification mark. 5. **Distributed trust.** Most verification is delegated to trusted verifiers and to verified institutions attesting their own staff, rather than centralised on any one platform. 6. **Transparent and appealable.** Eligibility, evidence standards, removal criteria, and appeals routes are published, and every loss of verification can be contested. @@ -27,7 +28,7 @@ ATProto already has most of the raw materials for an evidence-based model of tru - [ ] **Domain handles** let people use a website they control as their identity. - [ ] **Trusted verifiers**, scoped by domain, can attest the people they already know – such as newsrooms and press-freedom NGOs for journalists, universities for academics, professional bodies for licensed professions, or sector federations for cultural and sporting figures. -- [ ] **Labelers** let communities publish their own verification signals, which users and apps can choose to trust or ignore. +- [ ] **Labellers** let communities publish their own verification signals, which users and apps can choose to trust or ignore. - [ ] **Evidence-backed profiles**, as [Sifa ID](https://sifa.id/) is building, link each claim to its source: a commit, a publication, an ORCID record, an RSVP, or a post. - [ ] **Peer attestation** or **vouching**, as Sifa is designing and [Tangled](https://blog.tangled.org/vouching/) has implemented, lets already-verified people attest to others, with clear scope and reversibility. @@ -38,11 +39,11 @@ A deliberate consequence of being ID-free: **pseudonymous public figures can be ## Roadmap - [ ] Publish a shared vocabulary so that apps describe verification consistently ("verified by X for Y", not just "verified"). -- [ ] Document existing non-ID methods (domain ownership, cross-platform linkage, institutional attestation, ORCID, labelers, trusted verifiers, peer attestations) as a single reference for builders. +- [ ] Document existing non-ID methods (domain ownership, cross-platform linkage, institutional attestation, ORCID, labellers, trusted verifiers, peer attestations) as a single reference for builders. - [ ] Coordinate on a `community.lexicon.verification.*` namespace so attestations are portable across apps and lenses. - [ ] Store attestations primarily as signed records in the attester’s own PDS, propagated over the firehose and revocable by tombstone, following the lexicon-on-PDS pattern used by Tangled vouching. Labeler services may aggregate and surface them; the PDS record is authoritative. - [ ] Agree on a peer-attestation lexicon, building on [Sifa issue \#166](https://github.com/singi-labs/sifa-workspace/issues/166) and Tangled's prior art, with mindful design defaults: reversibility, optional reason, and clear scope. -- [ ] Pilot institutional self-verification flows with **Eurosky** for European officials, journalists, and NGO leaders, **La France sur Bluesky** for French institutions, and with **ATScience** for scientists and researchers, so that identity can be evidenced through institutional and publication signals rather than ID upload. +- [ ] Pilot institutional self-verification flows with **Eurosky** for European officials, journalists, and NGO leaders, and with **ATScience** for scientists and researchers, so that identity can be evidenced through institutional and publication signals rather than ID upload. - [ ] Develop criteria for revocation: acquisition by a conflicted entity, departure from published evidence standards, unilateral standard changes without consultation, or sustained inactivity. - [ ] Specify a machine-readable revocation signal so apps can detect revocations without manual review. - [ ] Agree on decay and freshness signals so old attestations do not silently confer present-day trust. @@ -64,4 +65,4 @@ Feedback channels: ## Collaborators -This draft is the work of an informal working group across ATProto. Initial collaborators include [Sifa](https://sifa.id), [Eurosky](https://eurosky.tech/), ATScience and La France sur Bluesky. Additional collaborators will be listed in the published version. +This draft is the work of an informal working group across ATProto. Initial collaborators include [Sifa](https://sifa.id), [Eurosky](https://eurosky.tech/) and AT Science. Additional collaborators will be listed in the published version.