Self-Sovereign Identity and the Future of Digital Trust — episode artwork

Join Paul Spain as he speaks with Drummond Reed, a global leader in digital identity, privacy, and online trust, about how self-sovereign identity puts control of digital credentials back in the hands of individuals. They unpack why privacy concerns remain central to government-led identity systems, and what the approaches taken in Bhutan, India, Utah, and the European Union reveal about the future of digital identity. Drummond also explores decentralised trust graphs, verifiable credentials, AI agents, and the growing risks of sophisticated scams and surveillance — and looks ahead to a world where individuals control more of their own data, digital agents act on their behalf, and trusted relationships can be verified without relying on a single identifier everywhere online.

Listen
Read the Full Transcription

Transcript is computer-generated and may contain errors.

Drummond Reed:
The term digital identity generally refers to any way that you're going to represent who you are online. The term self-sovereign identity came along to specifically say, wait a minute, there's a way of doing digital identity that puts the power and the control back in the hands of the individual.

Paul Spain:
The New Zealand Tech Podcast, brought to you by Gorilla Technology, proactive and strategic IT. Greetings, I'm your host Paul Spain, futurist and Chief Executive at Gorilla Technology in Auckland. Recently I've been delving further into the world of all things digital identity and trust. My interest, as with all technology, is to know how we can gain the most benefit from digital enablement whilst reducing and mitigating potential negatives. Most people I talk with don't like the identity theft risks of others holding a digital or a photographic copy of their traditional passport or driver's licence. However, many are also uncomfortable with alternative approaches that maybe would, would lead to high levels of proactive surveillance, as, you know, we're aware of in non-democratic jurisdictions. So on that basis, I'm interested in self-sovereign identity. This is a digital framework that promises to let individuals own, control, and share their personal data without depending on central companies or governments to have full control and storage of that private identity data.

Paul Spain:
So to learn more, I sat down with Drummond Reid, a leading global voice in digital identity and online trust. He spent more than 3 decades helping shape the technologies and standards behind privacy, security, and decentralized identity. Drummond was here in New Zealand very recently when I spoke with him. He is the co-author of Self-Sovereign Identity, a contributor to the W3C Decentralized Identifier Standard, and currently serves as director of the First Person Cooperative. So today we'll explore how self-sovereign identity works, what it means for privacy and government services, and how digital wallets, trust graphs, and AI agents could reshape the way we prove who we are in an online context. Before we begin, thanks to our show partners, One New Zealand, 2Degrees, Spark, PwC, Workday, SAP, and Gorilla Technology. Let's jump in. Welcome along to the show.

Drummond Reed:
I'm very glad to be here. It's my first full day in New Zealand ever.

Paul Spain:
Wow, a real privilege that we've managed to have you share some of the day with us, Trymond. Brilliant.

Drummond Reed:
Totally my pleasure.

Paul Spain:
You've come in from Seattle?

Drummond Reed:
Seattle.

Paul Spain:
Yeah.

Drummond Reed:
Yes. Which has Weather rather like this, only it's the dead opposite right now. I came from roughly 80 degrees Fahrenheit, and I'm glad I brought my ski jacket.

Paul Spain:
Yeah, fantastic. Well, I hope you get to experience some of New Zealand's best. I understand you'll be heading down to Queenstown very shortly, and then you'll be at an event in Wellington.

Drummond Reed:
Yes, and I look forward to seeing--- I have so many friends who gush about New Zealand. It's finally time to get to see it.

Paul Spain:
Brilliant, brilliant. Well, let's jump in. Maybe to frame the conversation, we hear, you know, we hear a fair bit in recent times around digital identity. Maybe you can share where self-sovereign identity and digital identity sort of fit in the picture and why self-sovereign? Identity is so important.

Drummond Reed:
And I'll say right up front, it has always been somewhat of a controversial term. In fact, one of my longtime good friends in the industry who unfortunately is no longer with us, Kim Cameron, who was the Chief Identity Architect at Microsoft, once said, I'll never use that term. It sounds like a hillbilly revolution. Right? Because he was equating it with, you know, the sovereign citizen movement.

Paul Spain:
Right, right, right. Which is fairly niche.

Drummond Reed:
It is fairly niche. And I think it's more of an American thing. But the way I would contrast it, Paul, is the term digital identity generally refers to any way that you're going to represent who you are online and prove who you are online, whether it's legally--- your legal identity, full identity, or some pseudonym, just the whole spectrum. And it refers to any kind of system you use to do that, whether it's centralized or decentralized or federated. all the options in between. The term self-sovereign identity came along to specifically say, wait a minute, there's a way of doing digital identity that puts the power and the control back in the hands of the individual. And the general mechanism to do that is ironically the way we do identity in the real world today, in almost any case, like the 36-hour trip I took to get here. I think I showed a passport or a driver's license.

Drummond Reed:
you know, half a dozen times. And so we put credentials in wallets from issuers we trust. We carry them. We decide as an individual who to show them to. They're very private one-on-one interactions, and we accomplish what we need to do. And the trust is in the issuer of those credentials, and then in me as the holder of those credentials to present them when and where I want. That's the control I have. I don't control what's on those credentials.

Drummond Reed:
The issuer has to say, we believe that's true. But as long as that's the case, it completes what we call the trust triangle. The issuer issues it to me, the holder. I show it to you, the verifier. You verify it or not. It's your decision. And that's how trust works in the real world. And all we're doing with self-sovereign identity, as we cover in the first couple of chapters of the book, is saying, hey, let's make digital identity work the same way.

Drummond Reed:
Let's have you have your own digital wallet. You get the credentials issued to you in a digital form, cryptographically signed. And then when you need to present that to a verifier, you're actually presenting what we call proof of those credentials. And they can cryptographically verify that proof is valid, which, by the way, cuts out a lot of the kind of fraud you could do with regular physical credentials. There is one other thing I'd like to point out right away, which is that proof of the credential, can actually be much more privacy-preserving, or at least as privacy-preserving as presenting it in person, because you only have to prove what that verifier needs to know. Classic example is you go to a bar, they only need to know you're over 18 or whatever the drinking age is. And if you do that with a physical credential, have you ever gone to a bar and had them say, I'm gonna take a photocopy of your credential?

Paul Spain:
Not in a bar, but I've had that happen in many other situations for sure.

Drummond Reed:
I've had it happen at a bar. I did not go into that bar. I just simply said, no, I'm not going to do it. Right. It's just like why they had that rule, I don't know. But with digital credentials and the right cryptography, all they need to know is, okay, I can prove I'm over the legal drinking age. They don't get any of the other information. So it's very fast, it's efficient, and it's privacy preserving.

Paul Spain:
There's a perception that I guess modern digital identity is being driven by governments and large organizations rather than by individuals. Who are you seeing as really pushing for a move forward when it comes to certainly self-sovereign identity? And what are the problems that you you see folks raising?

Drummond Reed:
Well, the number one problem is, to be frank, any form of digital identity that is then discussed in the context of governments raises the question of surveillance. It's just endemic. Any form of identity, even physical identity credentials, if it's a government-based system, there's always a question. what is allowing the government to surveil. With physical credentials, when they're handed to you, you're the one that's holding them. It's much less of a concern, but as soon as it goes digital, then it's like, oh, who can see that information? And every time, when you present a physical credential, except for when someone says, I'm going to take a copy of it, you don't worry about the information being memorized or copied. We all know that anything digital, as soon as you transfer it, it's just--- there's a perfect copy every time. And so the expectation is, wait a minute, if I have a digital wallet and digital credential, I can be surveilled every place I'm using it.

Drummond Reed:
I totally understand that concern. And it's taken us a long time. I mean, we're a decade into the emergence of self-sovereign identity for folks to understand, wait a minute, we can actually build cryptography.

Paul Spain:
Mm-hmm.

Drummond Reed:
that makes it safe or even safer than--- and more privacy-preserving than in the physical world, because you're only producing that proof that they need. Now, the next thing I'll say is governments that then decide, okay, this is a good technology for us to move forward with, to help adopt, either implement themselves or support industry in doing it, So there literally are fully public initiatives, fully private initiatives, and then public-private partnerships. I've seen all 3 all over the world. And I don't think any one of those is necessarily any better than the others. It all depends on the governments and the private industry and the regulations that they're doing. But what is happening now is the governments are interested--- if the government supports Privacy, digital rights, empowering their citizens. We can talk about some good examples, but the most recent one that's definitely worth going into is the state of Utah in my country, the USA, has adopted some of the most progressive legislation around digital identity in the world. If the government believes in that, and therefore they have regulations that don't prescribe the exact technology, but what the requirements the technology has to meet, Then if that's implemented, you're going to end up with a system that empowers and protects the consumer or the citizen.

Drummond Reed:
And at the same time, frankly, saves government money, makes it more efficient, helps it with digital transformation. It's a bunch of benefits. It's a win-win. And it's also a win-win for industry because the same credentials that citizens will now use with the government, they can use with business. They can use peer-to-peer, everybody wins.

Paul Spain:
And how different is what we're talking about in terms of self-sovereign identity versus a government managing and running digital identity, just say within government, and it's all your information sitting within a a government digital identity versus the self-sovereign approach?

Drummond Reed:
It's a great question. There's a--- I'll talk about real-world example. The largest government-run digital identity system in the world is Aadhaar in India. I believe it's 1.2, 1.3 billion people are covered by Aadhaar now. Aadhaar is--- I know some of the folks that have designed it. One of them is speaking at the Digital Identity New Zealand conference, the HUI, next week. And it's a very solid system and it is as secure, I think, as you can design a system of that size. But it is a central system with a biometric database for all the citizens of India.

Drummond Reed:
And it has been very empowering. It's been pretty successful. The adoption rate, I think, is over 90%, maybe 95% at this point. But it has raised a number of privacy issues. And the more that citizens and businesses want to take advantage of it, the more of those privacy issues have come up. So in that case, it's a totally centralized system. Every Indian citizen, their biometrics are recorded, and the information about them is in the government database. And as they're needing to use that identity, they're basically sharing an identifier of their information, that government database, every place they're using it.

Drummond Reed:
The contrast with a self-sovereign identity would be what has been implemented. I could use several examples, but the one I'll choose to use is Bhutan. For various reasons, including just an enlightened monarch, the current king of Bhutan, They decided that they didn't have a digital identity system, and in researching the options, it was interestingly just shortly after the book came out, they said, well, actually what seems to fit best for our country would be a self-sovereign identity system, which meant they were still going to collect biometrics to be able to identify the citizens, but only for the purpose of registering and issuing the citizen a government-issued identity credential into a digital wallet that the citizen--- the government actually developed the wallet. They used--- they built it on top of open-source software from the Linux Foundation. But every citizen could get their own digital wallet, the credentials issued into that wallet, and they passed what's called the National Digital Identity Act. one of the provisions of which made it illegal for anyone, including the government, to surveil the use of that credential or any other credential in that digital wallet. They basically made surveillance of their own digital identity system illegal. And they're quite serious about that.

Drummond Reed:
So they built privacy into the system. So in Bhutan's system, even though there is a biometric database into which you're registered in order to qualify for having that credential issued, so they know it was really you, Once that credential is issued, there's no accessing that database. You're using that credential, the government has signed it, you can prove that to any verifier. They also enrolled a good number of the--- a good percentage of the businesses in Bhutan early in the program to make the credentials and the wallets immediately useful. And it's been very successful.

Paul Spain:
So they're taking the biometrics. What does that mean? How does that look in practice? Where does the biometric data sit, and how does that get protected in that case?

Drummond Reed:
So again, there's--- different governments are taking different approaches. In India, centralized multiple biometrics, fingerprints, I think--- I'm not sure. I think it's fingerprints and irises. In Bhutan, I believe it's primarily irises. There is a government database in both of those cases where--- but it is the access to that database, the ongoing use, that is the difference between those two. In other places adopting self-sovereign identity paradigm, such as Utah, for instance, I'm going to call it, because the United States as a country does not have any federal identity system. It does have the Social Security number, but that's a tax number. It's never meant to be used for identity.

Drummond Reed:
And unfortunately, you know, went down that road, but for various historical and cultural reasons, there is not now and probably will never be a federal government identity system. So that is a--- it's a state function. So every state can decide how to do it. In the US, the default has become the driver's license. It's now become much more widely recognized that privilege to drive and an identification of a person are not the same thing, and you shouldn't be restricting people who can get identification to people who can drive or qualify for a driver's license. So, as I said, Utah, starting about, I think, 18 months ago, took a very enlightened approach and said, we're going to separate it out. It's no longer a driver's license. It's actually--- it's called a state-endorsed digital identity credential, or SEDI for short, S-E-D-I.

Paul Spain:
Mm.

Drummond Reed:
And the SETI credential is a pure identity credential. And what makes it fully self-sovereign is the individual is actually going to create their own decentralized identifier, a cryptographically verifiable identifier, and go to the government with that identifier and say, I can prove that I control this. And the government's then going to say, okay, we're going to collect some information to make sure it's really you. And we're now going to issue you a state endorsement of your own self-sovereign digital identity. That's this new paradigm of a state-endorsed digital identity. In that case, the biometric you would use to unlock your wallet never leaves your phone.

Paul Spain:
Right. So you're using--- if you're on an Apple phone, that's just effectively using your Touch ID or Face ID that's built into the operating system.

Drummond Reed:
Exactly. What happens there that's really quite elegant is both Apple and Google, there is a way for the phone and the wallet function on the phone to produce a proof that you have used your biometric to unlock, in this case, your wallet.

Paul Spain:
Right. So you can't get away with just using a PIN number. It's got to prove that it's you. And the only way to ensure that, because you can share your PIN number, would be your biometrics.

Drummond Reed:
Exactly. And the verifier can ask and say, you know, if it's a lightweight, we just need to know it's you coming back, they may not require it. But the verifier can, when they're asking for the proof, they can say, and I need a proof you used your biometric to unlock your wallet. That's all they learn is you used your biometric to unlock your wallet. You did it on, you know, we trust Apple saying it was an Apple phone or Google saying it was a Google phone or Samsung, whatever. But they never see the biometric or anything like that.

Paul Spain:
Yeah.

Drummond Reed:
Yeah.

Paul Spain:
That sounds good. Now, so it seems like, yep, India is kind of their one approach. Utah's maybe other end of the scale. Bhutan's approach sort of somewhat in between in that, you know, with Utah, you're really holding, you're fully holding all that data, whereas Bhutan, that is sitting in a government Database.

Drummond Reed:
I'd say Bhutan is well across the spectrum towards full self-sovereign identity. The fact they take a biometric in order to be confident that it's you, and also another thing is that biometric helps them recover or helps you recover if you lose a phone or there's any problem, data gets corrupted. So There's a case to be made if you--- and Bhutanese citizens have a pretty strong trust relationship with the government. So when I was there, I went for the Bhutan Innovation Forum 2 years ago, the Bhutanese citizens were very--- there were no concerns about that aspect of the program. But in large part because that database was only being used for enrollment and verification. It wasn't like India where the database is constantly being checked. The surveillance issues were--- yeah, they weren't there.

Paul Spain:
Right. So you're not passing biometrics on an ongoing basis backwards and forwards.

Drummond Reed:
Right.

Paul Spain:
Exactly. What do you think are the biggest risks if we get digital identity wrong?

Drummond Reed:
Oh. So again, it does depend on the program. I mean, what we've been talking about so far is government-issued. credentials.

Paul Spain:
Yeah.

Drummond Reed:
I like to break digital credentials into 3 broad buckets. Government-issued is the first one and the most obvious one because that's how, you know, we think about a lot of conventional identity today and the first digital identity programs. The second one, and what some other countries like the UK have embraced, are credentials issued by private industry. Classic example, whether it's banks, healthcare companies, insurance companies, anyone that you have a relationship with, in many cases, a regulated industry where they need to know it's really you. They're in a position because of that relationship to issue you a credential. And many other verifiers, whether it's retail, travel, education, they're in a position to say, oh, that would be very very useful, right? It's classic, you know, what we call the trust triangle. Who trusts who? And the more points you have, the more trust triangles you have, the stronger the trust fabric and the more valuable that ecosystem is to everybody. So there's a network effect in there.

Drummond Reed:
And so those privately issued credentials have a lot of value. Some have leaned heavily in that direction, like I said, in the UK. There's a third bucket that I'll go on record as saying I believe will become the most valuable of all 3. And those are issued peer-to-peer. If you and I had the right app on our phone right now, we could issue what we call a verifiable relationship credential between the 2 of us. And we'd have another link in what we call the decentralized trust graph. And every community or group or business that you have a relationship with could also issue you one of those credentials. And you would gain stronger and stronger proof that you are a trusted entity with a number of verifiable trust relationships.

Drummond Reed:
And that is the work that I've been focused on for the last 2 years is building a decentralized trust graph. And I think that category of credential will be--- well, I'll put it this way--- at least as valuable as the other 2.

Paul Spain:
Mm-hmm.

Drummond Reed:
All 3 can happen in digital wallets that are designed to support them. And I think that's actually a very exciting future.

Paul Spain:
Now, how important do you think that privacy is? I heard it said today, Sir Ian Taylor was speaking. an event this afternoon, and he talked about making some information available online, some content that him and others have been involved in producing. And he said, we're going to make it available for free. And he said, and that means we're not going to ask for a name, email, anything at all. Because he said, as soon as you start doing that, there's a cost. How do we equate what's appropriate in terms of when, where, and how, and what we should be sort of sharing in these different circumstances? How do you look at that, Drummond?

Drummond Reed:
It is a very good question. One of the early and frequently cited concerns about any digital identity system is because it enables information to be shared electronically, which of course happens in a fraction of a second, it could lead to a digital, air quotes, paper please society, right? Papers please. That suddenly, because you now have the ability to share it, the verifiers of the world out there, the websites and services and things that are always, you know, for where we need accounts, we need to protect our information, they'll just start asking us, share your driver's license, share your passport, you know, share your proof purchase history, all the things you can now prove electronically. It's a legitimate concern, but right at the outset, those of us working on it said, well, there's actually--- there are 2 countervailing forces in that. One, government regulation. Interesting enough, I would say outside of India, the largest digital wallet, digital credential effort in the world is actually the European Union. what's known as European EU Digital Identity Wallets Initiative. Technically, it's the eIDAS 2.0 regulations, are mandating that every EU member state shall make a digital wallet available, a certified digital wallet available to all of its citizens by the end of 2027.

Drummond Reed:
And in addition, will issue what they call the personal identity credential into that wallet. and every other member state shall recognize the validity of that credential. So throughout the European Union, you know, if you're a citizen of Spain and you want to go take a holiday in, you know, France, your credential will be accepted. You want to open a bank account there, it's just--- that's the whole idea, make portable digital identity across at least all of the EU. They do care about the rest of the world, but right now they're focused on Let's make it work there. That's been a lot of work. There's whole conferences that are focused on all the things that are necessary to make that work. The privacy community in the EU, and we know that's the home of where GDPR and other world-famous privacy legislation come from, initially was extremely concerned about will this lead to papers, please? Built into the regulations was, well, the way the EU will handle that is all the verifiers have to be registered as well.

Drummond Reed:
If you want to ask for information related to that PID credential, you as a verifier, a website or an application or a bank or an insurance company, you must be registered yourself and you're regulated in terms of what you can ask for. So you basically--- it's just sort of like an extension of GDPR. If you're asking for something that is not what you need for in the context of that transaction, transaction or that relationship, you can be penalized, you can be fined for that. And so they're basically saying the answer is regulation. The other answer that I think is going to be more powerful over time is going to be the privacy equivalent of crowdfunding. In other words, in order for a verifier, if you were going to a website, for instance, that was asking for a lot more information that it didn't need, The fact that their request is delivered electronically to you is verifiable from your side, and therefore I call it the 1,000 eyes. Now everyone can see, wait a minute, that site in the context of what you were asking for is asking for way too much information. Well, everybody can see that that's the case.

Drummond Reed:
So unlike physical interaction where you're the only one in the room and you could like, well, I don't think that's appropriate, but who else can actually prove it? Well, if they're doing it digitally, everybody can see it. So it is a market self-regulation thing that companies that overreach, it'll be a reputation hit very quickly.

Paul Spain:
Right. So somewhat like what we've seen with applications that ask for your location and all sorts of other data that they shouldn't have. It's very public if somebody puts out an application that's asking for that sort of data.

Drummond Reed:
Absolutely.

Paul Spain:
Interestingly though, on that front, and I think I've got the right company here, Temu, before they were Temu, another company, I think I'm getting these things right, they launched an app that was banned from the app stores because they were asking for too much.

Drummond Reed:
Right.

Paul Spain:
So they dialed it down and relaunched under a different name. And yeah, still have sailed probably very close to the sun on that front. So there is, and if you look at the scale of their success, it's huge. So there is a level to which the general public, if they're enticed in one way or another, pretty much ignore---

Drummond Reed:
Yes.

Paul Spain:
You know, might be in theory self-policing, but there is that degree in which there's a financial incentive or what have you to participate, then that the privacy can go out the window, can't it?

Drummond Reed:
It absolutely can. I mean, that's many famous experiments, but giving away your privacy for a candy bar. And I don't dispute that. It's sort of a cliché in the industry that you can't count on people caring about privacy, at least especially in the Western world, where economic factors, play more than cultural and sometimes government factors. I do want to say that that is true in the internet and the web as it exists today. When you start to build a decentralized trust graph and you add what we call verifiable trust agents, they're able to pick up on that bad behavior without people having to do anything. And when that's happening, you have a much stronger form of protection. Think of it as sort of crowdsourcing those 1,000 eyes.

Drummond Reed:
Now those 1,000 eyes have AI agents working for you. Now that's a very important part of it. We haven't talked about AI yet, but if you have what we call a verifiable trust agent working with you, now a lot of those things that you don't have the You know, either desire or cognitive capacity to, you know, to examine, like all of those thousands of privacy policies that you haven't read, Paul, and you clicked you agreed because you read them, right?

Paul Spain:
Yeah.

Drummond Reed:
Well, now guess what? You can have an agent that has read it and actually told you, oh, Paul, there's 3 things about this one that you need to see. As soon as that's As soon as we level the playing field that way, it's going to be, I think, a very powerful force to even up the frankly tremendous asymmetries in power that exist on the web today.

Paul Spain:
I think there is that, as we talked about, there's that worry of you're not just tracking, sort of dehumanized social scoring. How do you see self-sovereign digital identity, self-sovereign identity, pushing back against those concerns?

Drummond Reed:
It's a very good question, and it is one of the main reasons I'm working on--- again, I think of the--- call it the second generation of what we called self-sovereign identity. Actually, it has a name. We call it verifiable trust infrastructure. With verifiable trust infrastructure and a decentralized trust graph, You have--- you're empowering every person and every community, which includes every business, all the way to governments. Everyone can be sovereign. Everyone can form the relationships that they trust and then make proofs about that. So if you're in a culture or society that sanctions social scoring of some kind, and they have the surveillance system in place, this doesn't necessarily change anything about that. But what it does is it introduces--- it's a little bit like the introduction of the internet democratized the sharing of information every place.

Drummond Reed:
We believe the introduction of the decentralized trust graph will democratize trust relationships, make it harder for the asymmetries or in some cases the government systems that tilt things very much in one direction. It just makes it harder for them to swim against the tide. So I know it's a broad answer. There's so many ways, so many factors involved with who can watch what. But the one thing I will say about decentralized identity, self-sovereign identity, and the decentralized trust graph is all those relationships are mutual private agreements between those. The credentials, if you and I exchange verifiable relationship credentials, you have a credential in your wallet, I have one in mine. We now have a private channel we can use between us for whatever we need to share, and no one can surveil that because we have the keys on both sides, right? That's the way we have relationships today, just between us and the websites that are using SSL certificates, and we're saying, yes, it's an encrypted channel, but it's only those websites that are protected that way. Or we have to use applications like Signal to have a private channel, but then we all have to be using Signal.

Drummond Reed:
And with what's being developed now, digital wallets, digital credentials, digital keys, and the decentralized trust graph, we'll be able to use that everywhere.

Paul Spain:
I guess the other piece that fits into the picture is the sharing of data. So if a private entity shares data with another private entity, obviously that has, in theory, has to align with whatever the legislation is where those entities operate. And if a government entity wants to share data with another government entity, again, that comes down to the legislations and so on that are relevant. However, these things tend to tend to sort of grow over time. I've seen in New Zealand, one of our--- we've got a bit of a duopoly when it comes to supermarkets. You know, 2 sort of, well, 3, 2 key brands sort of behind the retail supermarkets. And one of those recently has rolled out a new Loyalty program. Loyalty program.

Paul Spain:
And there's been some pushback on social media and so on around this need to use this loyalty program because they were then able to link you up with varying data, which is obviously helpful commercially, but it leaves some folks sort of feeling a level of surveillance. And, you know, of course there's that sort of potential not just within the commercial world, but within, you know, the government landscape as well. How do you tend to look at, you know, what we should be doing as a society to get those pieces right? Can we set things in stone that aren't going to change? It seems that that's not really--- that's not possible, right? Things change over time. over time, but there must be some good takeaways that you've landed on.

Drummond Reed:
Yes. Again, I want to explain how I think that we can create a different--- both a different environment and a different set of incentives for what is driving data sharing today. That data sharing that takes place today is under our current paradigm where a New Zealand resident that uses either one of those supermarket chains, right? I mean, supermarkets. Today, your buying history there, and if you opt into that loyalty program, you're setting up an account. And all that data is being collected by the supermarket, right? It's a very one-way type of relationship. You don't have the power as the individual consumer to do anything about that, right? Because they're accumulating the data, that creates value for them, which now makes it attractive for them to want to share it or sell it, right? That's what's driving most of the data brokering economy, not just here in New Zealand, but throughout most of the world, right? Even folks would be surprised, that's actually quite a substantial part of the happening even in China.

Paul Spain:
Right.

Drummond Reed:
And economies where it's much more controlled, but there's a lot of value in that data. With everything we've been talking about, when you give citizens, and now I'm going to say not just a digital wallet and digital credentials, but a digital agent that they can use and make the relationship two-way, right? Like say, imagine when you make that purchase, you get a receipt. a paper receipt. Now imagine it's a digital receipt. You're keeping your own purchase history. It's in your wallet and your agent. And now you have the ability to share it with the merchants that you choose to, or even services that say--- there's a very popular comparison pricing service in the UK. I can't remember the name right now.

Drummond Reed:
But you do just that. You share your billing history. I think it's for energy. And they will give you recommendations. And it's a nonprofit, a public benefit, and it's very popular because it's made--- it's dealt with the information asymmetry in that market, right? Well, with digital wallets, credentials, and agents, we're going to be able to deal with that asymmetry in many, many different places. And you've changed the dynamics of the whole market. Now you are the valuable entity as an individual or your family, right? Your purchase history as a family, your purchase history as a neighborhood or community group, right? Everyone will be able to do this. And that will be the really valuable data because it's not just the data, it's the relationship, right? That's what the merchants and businesses are ultimately after.

Drummond Reed:
They're taking all that data so they can sell you more stuff and build a relationship with you. Well, now they can have the relationship directly. It's higher trust. It's a win-win. This is what we're trying to make happen.

Paul Spain:
And when it comes to governments collecting data, what are you seeing out there? Are there any significant changes? It seems like in New Zealand, we've had very limited ability for one government department to share data with other government departments.

Drummond Reed:
Yes.

Paul Spain:
But that seems to have been softening. So it seemed to be very much baked in, you know, whoever set that in place was very clear that we shouldn't just allow government departments to be, you know, firing data backwards and forwards. But that practice in a more technological world, as we sort of come to, I guess the digitization of everything, that practice seems to be falling away. Is that a concern?

Drummond Reed:
It is, and not just in New Zealand. As data becomes digitized, it flows more easily. And the way I would put it is the temptation to share it for mutual benefit with whoever you're sharing it with, whether you're selling it or you're trading on it in some way, just goes up and up, because it's just easier and faster when it's in digital form. So again, I think the only really structural answer to that is legislation can help. And I want to call out what Utah in particular is doing about it. But I think what will help as much, if not more, is when you empower the person or citizen or group or community whose data is being collected to be able to share that data directly, to control that, because now it switches around the other way. Now it's very easy for them to share it. See what I'm saying?

Paul Spain:
Just break that down. What do you mean by sharing it directly compared to how it's been done previously? How's that different?

Drummond Reed:
Give me an example of a government agency that would be collecting data that they would then want to share in a way that you might be uncomfortable with.

Paul Spain:
Right. So let's say it's the entity that's tracking your vehicle usage because you need to pay a tax based on how much you use the road. So road user type charge.

Drummond Reed:
Yep.

Paul Spain:
You might not want that information just to be available to any government employee anywhere in the country to be able to look up and say, oh, Drummond drives 17,000 miles a year or whatever the, you know, whatever the number is. Oh, and here's all the data of exactly where he goes any time or day. So if that were to leak, whether it was police have access to that, you've got a bad actor within police that wants something that you've got, well, you know, et cetera, et cetera.

Drummond Reed:
It is a perfect example because it's one I actually worked on in my period at GenDigital. which acquired Evernym, where I was chief trust officer. And the perfect use case that we can talk about here is that data that you just talked about, your driving--- I'll just call it your driving history data. In the industry, it's called your telemetry data for your car. Is very valuable, at least to one party, and that's an insurance company, right? Because they can more accurately predict the rates that they would need to charge and still be profitable, right? you could absolutely see the insurance companies saying, oh, if we know the government's collecting that data, there's a very strong temptation for the insurance companies to say, government, we can pay you for that data and you can, you know, deal with your deficits and we can get the information we need to better serve our consumers. That's how they would put it, right?

Paul Spain:
Mm-hmm.

Drummond Reed:
The alternative is that data can be either collected by the government and shared back with the individual, or that data can actually be collected by the individual. And I know that's possible because one of the companies that does that, it's a Belgian company, that app will run on your phone and you have the data. You then share it verifiably with whomever it needs to. And in that case, it was actually one of the largest insurance companies in the world. I won't name the company, who said, oh, that---

Paul Spain:
That's interesting.

Drummond Reed:
Data is valuable not just for your insurance premium, but actually to help you be a safer driver. And they wanted many more people to start doing that. It's called Safe Driver Program. And there are a bunch of US insurance companies that have those applications. But the privacy issues are what holds back a number of those people from adopting those. They've reached a certain market penetration. And in order to get beyond that, they need to solve this privacy issue. Well, The answer is they don't.

Drummond Reed:
You collect the data, you share the information they need to give you that rate, and you choose who you share it with. So now it's a competitive market. That is a much deeper structural answer. And that's, that's empowering. So anytime you or your agent could collect that data and it will be under your control, I would argue you're going to be better off. And the government won't be better off.

Paul Spain:
I'm interested in the role of agents in AI. You've been, you know, mentioning them. How do you, how do you see that fitting together in, in simple terms?

Drummond Reed:
That's actually the main topic of the talk I'll be giving at the Huitamata next week for Digital Identity New Zealand. In the talk, I'm going to say it's about the internet of Humans and the Internet of Agents.

Paul Spain:
How do you describe those 2?

Drummond Reed:
The Internet of Humans, the problem you're solving there is, in the industry, it's known as proof of personhood. And it's actually one of the oldest and hardest problems in all of digital identity. How, Paul, can you show up at some website or some application and prove you're a real person? How do you do it today, Paul?

Paul Spain:
With a CAPTCHA and those sorts of things.

Drummond Reed:
Exactly.

Paul Spain:
To prove that you've--- well, whether it does or doesn't prove it as AI gets better. And then I guess there's proving, are you human? And then it's, well, which human are you?

Drummond Reed:
Yes, those are the 2 dimensions of it. I love asking this question. You've been online for years. Roughly how many CAPTCHAs, if you had to guess, Have you filled out?

Paul Spain:
Too many.

Drummond Reed:
Yeah, it's probably in the thousands, right?

Paul Spain:
But I understand the need.

Drummond Reed:
Oh yeah, yeah, exactly. I mean, sites don't like having to put in CAPTCHAs. They do it because otherwise they would be overwhelmed by bots. It would just literally put the sites out of business. The problem with CAPTCHAs is the bots are now better than we are. AI has completely changed the game. I mean, when you think about it, and people--- if you understand, of course, how AI works, that AI systems are trained, guess where that training data is coming from for all those CAPTCHAs? From us, the humans. We are teaching the AI how to solve CAPTCHAs.

Paul Spain:
Yeah.

Drummond Reed:
Give it enough training data, and the AI, by definition, is going to be better than we are. So unfortunately, that applies to almost everything we do online to prove that we're humans. The way we do that is teaching AI how to impersonate that. That's why you now have AI voice. 3 seconds of your voice is enough for an AI to imitate you well enough to commit fraud. That's one of the classic things now, right? Call a random phone number, get someone to answer it, especially a child. 3 seconds of their voice. Now everything is set up, it's run through a system, and at some predetermined time when they've figured out based on the telemetry they've done around that phone number that there's an adult, especially an older adult, at that house, they'll call at a time that the adult is probably going to answer the phone and run the scam, right? Your child is--- we have your child, it's kidnapped, or they need, you know, they've--- They've been kidnapped.

Drummond Reed:
All the classic things you read about in the paper, right? Those are all AI-driven scams now, and they're getting easier and easier.

Paul Spain:
Mm-hmm.

Drummond Reed:
That proof of personhood problem is becoming existential. It is the worst cybersecurity threat. The statistics we had at GEN were just, you know, the numbers were going off the chart. So solving proof of personhood is, we need a solution that can be deployed widely, and is privacy-preserving. That's why I finally left GEN to concentrate for last year on the First Person Project, and that's where the decentralized trust graph work came from. We need a way for you to prove you're a real person very easily, any site, any place you go, using a digital wallet and a proof of personal credential.

Paul Spain:
What are the challenges that you've encountered so far with getting organizations on board with this decentralized approach?

Drummond Reed:
It is an uphill battle. I like to make the analogy to how the internet got started and how the web got started, right? If you describe what the internet could do before the internet was there, a lot of folks would go, I don't understand, I've never seen anything like that before, right? A smaller set would go, oh, that would be super That'd be fantastic, but someone else has to do it. And a very small cell would say, oh, this is gonna change the world and I'm going to go get it started. Internet had to get forward-leaning network owners to agree to add the protocol and start connecting their networks. Once that happened, the network effect kicks in and now we have the internet. Same thing happened again with Tim Berners-Lee and the web. Right? The web didn't appear overnight. It was a handful of universities and research labs saying, oh, if we could share information, research information and government information, we just solve our own problems, standardize the protocol, boom, right? Now we're in the phase where this needs to happen for digital trust.

Drummond Reed:
And what's happening is it will start--- our motto at the First Person Project is one person and one community at a time.

Paul Spain:
Right.

Drummond Reed:
So where, for example, are we starting with a decentralized trust graph? Who is adopting it first? As it happens, the standards and the open source code are all in projects at the Linux Foundation, the world's largest open source foundation. Well, guess who has a decentralized trust problem? The initial problem was a malware injection attack on not the Linux kernel itself, but a utility that is shipped with it, very popular utility called exeutils. This happened, I think it was 2023, and it was a 2-year social engineering attack for what looked like a developer to get maintainer status on that utility, this little utility.

Paul Spain:
That's right, that's right.

Drummond Reed:
Exactly.

Paul Spain:
And he built the trust, right?

Drummond Reed:
Over that period of time.

Paul Spain:
Over that period of time, right. He built the trust. He'd never been met in person.

Drummond Reed:
And furthermore, it became clear afterwards it wasn't a person. It was a state actor and a whole team behind it. It was brilliantly done because when they finally got that maintainer privilege, they waited, I think it was, I don't know, I think it was about 45 days or something. And then they injected it, very cleverly injected too. So it was only an assiduous Microsoft engineer that happened to notice some strange network There was some latency, wasn't there, or something that caused--- Yeah, it was just--- and it was---

Paul Spain:
I'm thinking of the same one.

Drummond Reed:
Exactly. It was a very small amount. There's a great Wired magazine article about it. Yeah. And, and he decided to dig into it and the further he got, and then when he finally found it, it was before there'd been wide distribution of that next--- it was really close. It would have been the worst malware attack in history. It would have been a backdoor in pretty much every Linux server out there, at least in that distribution which was the major one. So anyway, this scared the pants off the Linux Foundation leadership, and they just said, we have to provide better trust for our open source projects, starting with the Linux kernel, the most valuable, most widely distributed open source project in the world.

Drummond Reed:
Shortly after that happened, what started as a Hyperledger project at Linux, all the blockchain work that was going on at Linux Foundation, transformed itself and said, let's actually tackle everything in the area of decentralized trust. So it was called LF Decentralized Trust. When they transformed it and started that up, Jim Zemlin, the CEO, gave a talk about this exit utils attack and said, you need to solve this problem for us. Let's develop the solution that we're going to implement. And that's when we first told him about the First Person Project. And he said, okay, good. I want you to start with the Linux kernel. We're like, what? The first place you want us to take this, you know, new solution is, you know, the world's most valuable open source project.

Drummond Reed:
And he said, yes, they have what's called a web of trust today. And it's old, it's manual, it's slow. This is the modern replacement. How fast can you do it? And, you know, at that time we were an all-volunteer project and everybody were like, okay, we'll go get it done. And that was about 18 months ago. And in October, we're going to Linux, it's called the Plumbers Conference, and we're going to show them the solution.

Paul Spain:
Wow. Is there more you can talk about on where SSI fits in with personal AI agents? Is that something we could delve into?

Drummond Reed:
Absolutely. When you first asked about the relationship with AI agents, I started with the proof of personhood problem.

Paul Spain:
Yeah.

Drummond Reed:
The reason I started there is because the number one issue with AI agents as they start to become fully autonomous and can take actions, not just provide advice, is proof of who they're working for, right? Technically, it's authenticated delegation. Right.

Paul Spain:
How---

Drummond Reed:
if you have a personal agent working for you, Paul, how, when he goes and buys something, can that merchant say, I know it's working for Paul. In fact, I want proof that Paul authorized this agent. If you back up on that problem, it's like, okay, we can solve that with a credential, but how do you prove it was Paul? How do you prove you're a real person and it's not bots spinning up bots spinning up bots? Right? So it turns out proof of personhood problem is the key to solving the proof of agenthood problem, and it's the same architecture. You are in the decentralized trust graph, and then you have a relationship with your agent, or all your agents. You issue them credentials, and they can--- what they're delegated to do, what the scope is, what the expiration is, There are--- it is the hottest area of AI standards development right now. I have lost track. I think there are at least a dozen proposals from different companies, from Google and Anthropic all the way, and OpenAI all the way on down. And we're excited because we believe that all of those different ways of doing it are going to have to chain back to proving proof of personhood and how we're going to do that in an open and interoperable way.

Drummond Reed:
And that's what we're working on. in what's called the Decentralized Trust Graph Working Group at Trust over IP.

Paul Spain:
Great. Now, what practical steps should individuals and organizations be taking now to move towards a better future that adopts, I guess, the best of self-sovereign Oh, that's a big, broad question.

Drummond Reed:
So first of all, I would say the initiatives that are underway, the ones we've talked about, and I mentioned Utah a little bit, but I want to be specific. At the WHOI coming up next week, another one of the speakers is the Chief Privacy Officer for the state of Utah, a gentleman named Christopher Bramwell. He is fantastic, and he and his team have been helping lead the legislation there, and it has this really, besides taking the right approach of it's state endorsement of your own digital identity, which means if that credential's ever revoked for any reason, you still have that identity and that identifier, and you could, you know, you move to another state, another state can endorse it. You don't lose it. You don't have to get a different credential and prove, yeah, I'm the same Paul that I was before. So that's one advantage, but in the legislation, they went to the next step and they said, We want to build in what's called a fiduciary duty of care of anyone asking for that credential. And it basically reaches out to all those verifiers out there and says, yes, this is an open system. You can ask for that credential.

Drummond Reed:
But if you do, under the state of Utah, if you're covered by our laws, you have a duty of care on that information. You can't just go and sell it. You can't just say, well, our privacy policy is this or that. No, you actually have to have--- A fiduciary duty to take care of that data in your best interest. It is revolutionary. At this point, I believe it's someplace between 12 and 14 other US states are now signing on into a coalition they're putting together to make this effectively the state-level standard in the US. It's a huge--- So I actually want to say, One of the best things I think everyone could do, governments and their citizens, is get behind doing self-sovereign identity. If the government's going to do it, do it the right way, right? Bhutan drafted a National Digital Identity Act.

Drummond Reed:
It was passed almost unanimously by its parliament after they had about a year's worth of education. Why should you go this direction? Utah's legislation was passed unanimously. Now imagine how hard that is in any US state right now, right? Both sides of the aisle, everyone said, okay, this is a really good idea for the government, for the citizens, everyone wins. So that'd be the first thing. And the second one is I would say, as these solutions start coming out into market, try out a digital wallet. We're going to start having, I think by early next year, you're going to start to be able to use wallets that support the decentralized trust graph. You can start building your own relationships person to person. One of the places to do that very effectively turns out to be events like the one you and I were at earlier today.

Drummond Reed:
Guess what? You want to go to that event, you have to show up in person. They know you're a real person and you attended that event. That's a credential you can get. It's, it's good for you. It's good for the conference. And now you're accumulating evidence of your, you know, personhood and your trustworthiness as an attendee of that conference. That's why I said earlier, these peer-to-peer issued credentials or community issued credentials, they have a lot of value. So that's probably as far as I can go.

Drummond Reed:
There are a couple other steps we're taking, some of which I'm discussing with Andy, and we're saying, okay, we can't, we can't talk about that one yet because he wants to, you know, put together, you know, coalitions around it.

Paul Spain:
Now, you mentioned before the Social Security number, you know, in the US as, as You know, one of those things that's been used sort of far and wide, well beyond its initial intentions. Obviously every country or state and so on, there's a whole range of things in New Zealand and most countries you're going to have driver's license numbers, you're going to have a tax ID here that's your Inland Revenue Department number. These can be used as a sort of a common link from between one database and another. How are you seeing in the world going forward that will look? Is there any way to sort of stop that type of very quick and easy linkage? Obviously, in a lot of cases, it can be done just by looking at somebody's name, And a birthdate. All right. Does that type of sharing get any easier, any harder?

Drummond Reed:
So I'm going to--- because you're touching on the aspect of my 30-plus-year career that deals with identifiers, I'm going to give you a very crisp answer. But I'm going to tell your audience, you're going to want to dig in to really understand this. We have that kind of identifier sharing today because of our limitations as humans. We need human memorable and readable and easily shareable identifiers. Okay. We have carried that into our digital lives, right? Email addresses, almost every website or any place you're asked to register. Of course, they needed to correspond with you, but also, of course, that's Trackable everywhere you go, but that's nothing compared to your mobile phone number. That is the most tracked identifier you have out there today.

Drummond Reed:
So people worry about their government IDs. That's not the identifier people--- it's your mobile phone number. And how many people are willing to give up having a single mobile phone number for the--- So what we are building into this infrastructure, not just self-sovereign identity, but the entire decentralized trust graph, Imagine every relationship you have has a unique identifier that you're sharing just in that relationship. It's all private by default. Nobody could correlate you just on the basis of having that, right? Your tax ID, your insurance ID, they're all unique because they're cryptographically verifiable identifiers, decentralized identifiers that are minted for every relationship. You don't need any centralized registry for that. You are the registry. It's like having a unique phone number for every address in your address book.

Drummond Reed:
That's the default. Now, how do you actually prove you're the same Paul across those relationships? Now you control that. We call that a persona. That's another DID, but you share it only with the people that you want to say, oh, I want to know that these people in my political group all know I'm the same Paul, and these people in my social group, and these people in my employee. And you make that something that's easy to use because you use agents to help manage it. So I know it sounds like, oh, that sounds very complex. This is actually infrastructure we have to have to make AI agents work anyway. All the AI agent proposals out there are basically saying, well, Of course, your agent can't be giving away your identity.

Drummond Reed:
So it's got to be built in there. So we're finally seeing the uptake on what's now a 5-year-old W3C standard because the agentic economy will require it. So as much as people are concerned about, oh, AI agents and the world of AI could lead to surveillance worse than we've ever had before, it could also lead to better privacy than we've ever had before if we do it right. So yeah, it's almost like we need a whole other podcast to really explore that, but that's as far as we can probably go today. Yeah, yeah.

Paul Spain:
Okay, just to close off, to ensure that as a country that we respect cultural values, respect each individual, do you see that there are some some extra things or some new things that we need to be baking in from a legislation perspective?

Drummond Reed:
I don't know what the possibilities are, but having now helped with several legislative, the largest one being the National Digital Identity Act in Bhutan, I think it would be fantastic. I actually think the Bhutan legislation is a good model, and in fact, the Utah legislation improves that. even more. If it's a possibility here for those, for the, you know, for the New Zealand legislature to get behind those provisions, it would be fantastic. And I know there's--- I know that Christopher Bramwell and the team in Utah are reaching out, not just other states, but they were just in the UK and in Europe earlier this summer. They're willing to work with anyone in the world that wants to do that. I'm actively helping them, many of us in the industry.

Paul Spain:
industry are.

Drummond Reed:
One of the reasons I'm here, that Andy Higgs invited me down to the HUI next week, is because his sense and a number of folks, I've been hearing it all day today, feel that New Zealand has a special opportunity to do this. It's cultural, it's geographic, it's your reputation in the world. I think he's right. I think it really--- there's a very special opportunity to do this. And I'm not the only one. I think many folks out there that are helping try to build this infrastructure would love to help you do it.

Paul Spain:
Thank you so much for being generous with your time and sharing. Thank you very much, Drummond Read.

Drummond Reed:
Thank you very much, Paul. I look forward to this. If things move in this direction, I hope we can do subsequent podcasts that talk about what's the actual progress we're making. people and companies and organizations and communities here in New Zealand and the government get involved.

Paul Spain:
Excellent, thank you so much. Well, I trust you enjoyed hearing from Drummond Reid and you now have a better understanding of self-sovereign identity. If you'd like more information on this topic, I'd encourage you to visit our new website at nztechpodcast.com and to sign up for our email updates because we'll have More info coming through there soon, including some visualizations that I've found quite helpful in getting my head around some of the details of this topic. Of course, a big thank you again to our incredible show partners who make the New Zealand Tech Podcast possible. So thank you to SAP, Workday, PwC, Spark, 2Degrees, OneNZ, and Gorilla Technology. Well, that's us for this episode. Thanks for listening in, and we'll catch you again on the next one. See you then.

Paul Spain:
This is Paul Spain signing out. Thanks for listening in, and we'll catch you on the next episode. This is Paul Spain signing out until next week. The New Zealand Tech Podcast, brought to you by Gorilla Technology, proactive and strategic IT.

← Back to all episodes