NEAR - Sponsor Image NEAR - Confidential swaps across 35+ chains Friend & Sponsor Learn more
01:26:02 · 3 years ago
Ethereum

187 - The Ethereum Attestation Service

EAS is a new public good, open, permissionless, and token free. Is this the key unlock for decentralized identity through crypto?

Up next

All episodes

Inside the episode

On today’s episode we welcome Bryce Patrick and Steve Dakh from the Ethereum Attestation Service. EAS is a new public good, open, permissionless, and token free. Is this the key unlock for decentralized identity through crypto?


TIMESTAMPS

0:00 Intro

7:27 What is an Attestation?

11:51 Attestations as a Primitive

14:35 What Are The Good For?

19:15 Defining Identity

22:39 Primitive Before the App

25:55 What is EAS?

30:31 Attestation Form Factors

36:51 Use Cases

40:19 EAS Growth Goals

42:17 Why Do We Need Attestations?

46:10 Why Build This on Ethereum?

52:46 Who is Using EAS and For What?

1:00:04 Web2 vs Web3 Attestations

1:05:17 Decentralized Reputation

1:08:05 The App Layer on Top of EAS

1:15:08 Privacy

1:19:48 Comparing To Sign In With Ethereum

1:21:22 How is it Funded?

1:25:08 Soulbound Tokens

1:30:00 Closing and Disclaimers

-----

RESOURCES

EAS

https://twitter.com/eas_eth

https://attest.sh/

Steve Dakh

https://twitter.com/stevedakh

Transcript
00:00

probably 99 of all the historical video content that we have right now and audio content it's probably all legitimate most likely not AI generated in the next few years you can kind of see how that can start to flip one of the things that we think about is like right now if you just if you take some historical content hash it time stamp it on chain using an attestation you can now prove you know a thousand years from now that this content existed before we had the AI capable to make a perfect replication of

00:30

that so right now we can actually use that to stations to almost save history and I think we should welcome to bankless where we explore the frontier of Internet money and internet Finance this is how to get started how to get better and how to front run the opportunity this is Ryan Sean Adams I'm here with David Hoffman and we're here to help you become more bankless the ethereum attestation service a new public good a standard that's open permissionless and free there's no token on this one we talked today about why

01:01

this might be the key unlock for decentralized identity and non-financial use cases in crypto as we've said so often on Bank lists First We Take Back our money then we take back our identity this might be a key to that solution a few things to take away from this episode number one why decentralized identity isn't a mystery it's actually just a bunch of attestations that were attestations that's going to be the focus of today's episode number two we talk about why web 2 and social networks like Twitter are actually just attestation silos number three we talk about why Financial use cases are going

01:33

to absolutely explode over the next 10 years as soon as we unlock the power of attestation and number four we end with thoughts on world coin on privacy on Soul bound tokens and a host of other items related to decentralized Identity David why was this episode significant to you the Arc of crypto is just iteration and unlock after iteration and unlock and I think this identity primitive of the attestation is a big unlock I think a lot of projects there's been a lot of teams and organizations

02:04

out there that have gone straight for the identity Golden Goose and they've they're skipping a step they're skipping a a layer and that is what I think is the ethereum attestation layer the attestation service that we are going to talk about here on the episode I think without the building block of attestations crypto will become much more is much more muted than it otherwise would be and in order to get to a much more expressive version of the crypto economic future we need these adestations to unlock new doors New

02:36

Opportunities because they bring in basically everything that's not money in finance into the fold of crypto and allows us to build on top of those layers and so getting to that point where we have identity and not just identity but everything that is related to adaptations you're about to learn all about that in the show in order to get there we need to First build out these building blocks that the ethereum adization service team is working on building today we have nothing to disclose for this episode but of course you can always check out bankless disclosures at

03:06

bankless.com disclosures guys we're getting it right to the episode but before we do we want to thank the sponsors that made this possible thankless Nation we are super excited to introduce you to Bryce Patrick and Steve Dak they are Builders leading the effort behind the ethereum attestation service this is we're going to refer to this by EAS in this episode and EAS is a free open source primitive that's deep in the ethereum tech stack and has aspirations to unlock an entire world of use cases using one simple primitive that of the

03:37

digital attestation Bryce Steve welcome to Bagless thank you thank you thank you Ryan and David it's a pleasure to be on the show we've been uh long time listener so to have the opportunity to come up is uh we're it's great we're excited to chat help educate more about attestations and uh yeah looking forward to the call I do think that this is going to be an educational episode for everybody including David and myself because um part of the reason we're having this uh this conversation is of course the bankless nation knows that identity is is very important to David and myself we often say first we solve money and then

04:09

we solve identity that's kind of like where cryptos is destined to go we also heard on the back of ethereum Waterloo from more than a few folks that you have to talk to the EAS team they're doing incredible things in the space this is a major unlock for on-chain attestation identity and so David and I like took a look um we understood a few things this looks like a you know open source primitive it's tokenless it's free it's a public good like these this is music to our ears on Bank list so we're hoping by the end of this episode we know enough about

04:40

EAS to be dangerous and we sort of get to get the shape of where identity might be going at least from a public goods perspective is that does that sound like an okay agenda absolutely yeah great okay well let's start here uh can you tell us it's in the name ethereum attestation service what is an attestation and What on earth does that have to do with the identity all right so um so basically simply speaking an attestation is simply an entity making a signed uh statement about something

05:12

uh in the in the case of EAS you're able to make an attestation about literally anything and uh you know that might not be you know the the reason why that's important might not be immediately obvious uh but uh that's why we have this story that we like to tell um so essentially uh we've been really super interested in solving decentralized identity and reputation uh and we know that it's like a super hard problem to solve uh identity

05:44

identity is uh relative your reputation is relative and it's contextual so for example my reputation to Bryce is different than my reputation to David uh you know and and it's a very complex kind of abstract concept that you know no one has really solved because you know I think people have been trying to solve it uh the wrong way almost building one layer too high and not building Upon A Primitive to be able to describe uh such complex uh things so we

06:18

started to think about uh identity and we're looking at all the platforms that existed out there you know today and we saw that most of the platforms that are doing identity they they're almost all like uh glorified kyc companies they build these like siled platforms that you essentially as a company or developer have to adopt and then you're kind of locked into that platform so say for example there's you know polygon ID or bright ID or any of these platforms

06:48

that allow you to do some sort of kyc they essentially are testing about you passing your kyc but that attestation can only be used within that platform and so if some other platform wants to kycu and you want and you're like some maybe a smart contract that wants to valid allow users only who are kyc to use it you'd have to implement every single identity platform and that just makes no sense for for decentralization it's non-interoperable and also none of it actually solves identity identity and

07:19

reputation is very uh complex I might you know like Bryce's you know selection and music but I might not like his food tastes but I might still trust him anyway so and we were thinking like what actually you know what actually is identity um and we started to think really deep about this and we started to think well you know at some point at some point we had no identity and then we did and so we were thinking well you know at what point was that and so like I

07:49

remember coming to this realization like when I was born my mom named me Steve right you could say that she attested to my name right and so I went to school and the teachers attested to my grades right and the kids in the class could have attested to whether they like me or not uh the the government attested to my passport and my driver's license uh University can attest to your diploma and your employer could attest to your

08:20

employment or whether you're a good employee or not and so we kind of quickly realized that actually you could represent identity and reputation as an aggregate of attestations about someone and so if you really want to be able to solve this problem what you really need to start with is a base layer where any entity can just attest about anything at all and so that was go ahead Bryce yeah and uh it's not that all the identity Protocols are moving in the wrong direction it's just that because there

08:52

hasn't been this primitive base layer everyone's building their own solution towards it and they're just one aspect of an identity and so we realize if you actually want to be able to solve reputation digital identity we need to have a Common Language and a framework that everyone can communicate off of so we've been reaching out to a lot of the identity protocols and Beyond with different use cases to really help try to bring everyone together when you guys say that attestations are A Primitive really gets me excited um especially when you define the

09:23

Primitive so easily as they just say statement that someone attests to something else and when it's when a statement like this is so simple you that you can get this Instinct that the expression of this primitive can be massive and I think the with trying to why these conversations around identity and these Primitives can be so difficult is that um a lot of the listeners especially crypto newbies new newcomers into this crypto world aren't used to thinking in these Grand terms and trying

09:55

to get people to understand this new form factor for identity is trying to also get them to understand these new monies that were created yeah you almost have to like unlearn the Paradigm of the dollar in order to understand you know Bitcoin and ether and in the same model you have to unlearn the fact that your government issues you your identity to really learn that actually your identity is an aggregate of all of your Social relationships that are like piecemeal together throughout time so maybe we can actually just go back to this primitive

10:26

with that shared kind of context and maybe Bryce you can start and Steve will go back to you like how does your identity form and how how is it a primitive like EAS actually the basement level Foundation that is actually needed to make one's true identity yeah if we check ourselves out of like blockchain altogether and we just think about how we interact with each other um offline and in the real world there's a lot of interactions that we have together imagine just like uh getting a loan for something you might go to Ryan

10:57

and say hey Ryan I need to borrow five thousand dollars well a simple IOU might be justified from Ryan to give you a loan because he trusts you and all the interactions that you guys have had in the trust that you've built but if you David wanted to go get a loan from A bank you might have to go to that bank and provide all these documentation you know all this documentation and all these different proof points actually show that you're a credible person and that's because you don't have that same Rapport and there's other regulations that they're they're following but the

11:28

idea is that all these entities are just making attestations about each other and the value of the attestation from uh you giving an IOU to Ryan is saying you know he's just trusting that you're actually going to follow through on that and so if we if we think about how how access stations can work it's really just like any interaction where you're trying to build trust and to make sure that the person on the receiving end like has some sort of authenticity that you are kind of who you say you are and like you have some reputation behind it you can unlock so much just just from that but we haven't had a way to do that online

12:00

and on chain is this just an identity conversation is this a is this a conversation specifically like attestations what do they do they give us our identities or is there something grander here so so attestations can be used for a lot more than identity we talk about identity first because we like to explain how like you can take such a really complex idea and uh describe it with something so simple but at the stations because they're simply essentially signed statements of

12:31

entities saying things about things it can be for anything it could be used for supply chain it can be used for voting it can be used for certification all sorts of things that aren't directly tied to Identity could be used for ticketing there's you know if you start and and what's interesting is in real life in in the real world we're attesting all the time you know we say things about other people we sign documents but there's never been like a digital way to do this in a structured uh standardizable way before and so that's what the the magic of like you

13:03

know with EAS being able to create a schema describing what you're testing about what you might want to attest about and then being able to attest with that scheme uh I think that's really the revolution that EAS has like kind of brought yeah if we think of like a notary service if you were to sign like a mortgage document or some sort of important document typically you have to get it notarized in front of someone that notary is essentially a testing that you were the person that signed that document but we don't have a way to actually have uh you know a way to

13:34

attest in a more structured way on blockchains we do have digital signatures which gives a lot of authenticity to who's signing and we also have the verified timestamp but we haven't been able to actually structure that in a way that is composable and more interoperable for people okay so I'm trying to like put put this together make this make sense in my own mind so a few things maybe have been talked about the the first I just want to make concrete is this idea of an attestation it's somebody saying

14:05

um a thing about someone else or making some claim right on chain what this mechanically looks like is on chain with say a metamask type of you know prompt I'm signing something with my with my private key right so I own rsa.eth that's my ens and it corresponds to an actual ethereum address and I can sign things uh on chain I can like digitally verify and I have to you know let's say I'm using my ledger for this uh Hardware device I have to you know or metamask I

14:36

have to click through and actually a test that something is true is that what you mean by an attestation uh is that all we're talking about here yep yep yes yes but but it is structured in a particular way okay uh you know with using the EAS standard but yes every attestation is signed with a with a wallet with a private key okay so that so you have the authenticity knowing that this attestation came from the entity that's claiming and so it's coming from The Entity that that owns those private keys that has like

15:07

physical access to those quantities or a smart contract it can even be a smart contract at a test right perhaps a smart contract receives some sort of inputs that it validates and then once it gets these proper inputs it attests to the entity that they've passed some sort of thing okay and and Ryan so like with social media today when you're posting something you're essentially just attesting to the post right and then if if David likes your post he's attesting that he likes your statement but we haven't had like a core building block to be able to do

15:38

that and I think one thing that we realize is like on chain is is really good for a lot of things but we also want to make sure that EAS was accessible off chain so EAS is also an off-chain protocol for making digital signatures as well okay okay uh I I want to get into yes but yeah that's that's an interesting point I guess all a tweet is is an attestation that my account the the person who holds my username and password and you know two-factor authenticated into my Twitter account is

16:08

saying this thing right and that establishes my my online Twitter reputation basically and is the basis for my social graph but I want to go back to something because um for for someone who's thinking like at the Primitive layer just signing something with a private key and saying yep I approve this message basically you're saying that that's essentially what identity is I think that's the the part that is a little bit mind-blowing at first and the part that's kind of like back to back to the basics of this is like what is money well it's a you

16:39

know a social scoreboard I guess and you know like we all agree something's money therefore it becomes money right that's what you have to unlock to actually understand money and to David's point it's something similar involved in understanding identity so all you're saying all my identity is is um attestations that my peers like that the the social context through which I'm in like make about me so like the nation state will attest that uh you know America hopefully they test this that I'm an American citizen and I have a

17:10

Social Security number and they will attest that right I mean whatever the government database somewhere and I'm also a Canadian citizen so the government of Canada will like attest that I'm Canadian and you know if like if I'm a member of a church or something then my church might attest that I'm a member here if I'm a member of uh you know some other community or if I'm a friend of someone uh then they might attest that I'm their friend like that's is that really all that identity is it's just like people attesting certain claims and there's nothing more than that so it's not it's not the claim so much

17:42

that is your identity it's how the entity looking at those claims values those attestations so for example if I show you an attestation from vitalik claiming that he believes that I'm a good person or something and you know it's what was signed from him you might find Value in that but maybe you know some Solana guy might not you know uh maybe maybe maybe someone who doesn't care about vitalik might not value that and so like it's it's very relative like if I was to want to take out a loan I

18:14

would probably show The Entity who I want to take a loan from attestations that are relevant that prove that I'm actually uh I actually pay back my loans and then I'm a real person and that I you know I have enough attestations where I don't want my record to be smeared you know and then that might be enough for that entity but for some other entity they might require something else and that's what makes it super decentralized because like instead of just having one entity saying like oh this person's a human trust trust us always right there could be other

18:44

entities that say you're human you know there could be friends that say that you're human and and depending on who you are and who's attesting you might value those attestations or not and so that's that's why I like this is the only way that I can imagine solving the decentralized identity problem you can't uh presuppose you know what identity he really is it can be it can be made up of a lot of things maybe I have an attestation that I was part of the Mickey Mouse club or something you know or something like maybe that's valuable to somebody somewhere but you know to

19:15

most people probably wouldn't care so yeah there's been a number of attempts at identity ever honestly even ever since the Bitcoin talk forums like the early people coming into this industry realize the relationship between private keys and identity you know if you sign a message and you are known to be the bearer of these private Keys then everyone can trust that you are the issuer of that message like even the or you know the Primitive days of crypto when we were in crypto Stone ages we still figured this out and then ever since then where there have been like a

19:46

smattering of attempts of like peop people in the application layer trying to go after identity right like World coin for example comes to mind versus recent recently going through the crypto meta but even before that right circles there was another attempt uh bright ID you guys listed them and these are all like identity apps and like that that one comic that one XKCD comic comes to mind where like uh there's 14 standards for identity we need to make another identity play that Aggregates all of them and then the next panel is like new

20:16

problem now there's 15 different uh identity standards I think what you guys are saying is is that all of those attempts at identity you can't go straight for identity at the app layer you need to build the base building block the Primitive down below and then maybe the applications can blossom can you can you guys talk a little bit more about why you need the Primitive before you have the app yeah and I as I mentioned before like all these identity Solutions they're all moving in the right direction and people will value like even with world's coin

20:47

right people have there's two schools of Camp one is like very like some people don't care to have their eyeballs scanned and then the other people do none of those people are wrong it really just depends on the applications of like do they care about world coins attestation that that person's a verified human and would they consider that as a part of their identity but if all these fragmented Solutions like world's coin bright ID um you know Etc uh are don't have a common layer where they can communicate you can't have an aggregate view of who someone might be and to give like

21:17

Builders and users the choice of how they Define like who's trustworthy or not and so while I think like all these are moving in the right direction they also tend to either tokenize or like try to extract value at the protocol layer um which if you think about like trust and like identity it's kind of like oil and water you can't really mix like finance and like trust and identity at the same layer because someone's going to come in with a bigger budget and try to direct The Narrative of like what is identity and it's usually for it might

21:48

be their gain right but if if we truly have a credibly neutral base layer where any entity can make these types of statements from that world coin and all these other um protocols can actually become more composable and actually helps them one of the things I want to add is uh in response your question is that with these companies if you don't have a base primitive you end up having to presuppose a lot about what identity is I think this is like one of the biggest fails of like you port they built in all of these presuppositions about what

22:19

identity is trying to use like did standards but there's so much more than just what's in that standard you can attest about you know there's so many different types of interaction intentions entities can have and you can't just pre-program them all in into a smart contract or an application I think that's where these platforms have failed because if you have to sign on to something like a uport then you have to just assume like viewport has everything that you'll ever need and if it doesn't then you have to use another platform and then you just create more fragmentation whereas like EAS uport

22:50

could use presuppose whatever they want to build a schema around that and a test with it and that's the cool thing about EAS like all these platforms that have their own standards can still build their own standards and use their own standards using EAS but they're still on the same uh the same layer like you any any smart contract can say I want I care about attestations from this entity or this entity or this entity when it comes to these types of attestations and that's what that's that's what makes it so much more interoperable interoperable

23:21

actually useful for decentralized identity and reputation okay so what actually is it so EAS it's not it's not just another identity play it's something it's we've been using this primitive word what but what actually is the thing like what actually is EAS is it an ERC standard like what actually is the thing yeah so so the EAS the it has two basic uh parts to it there's two smart contracts one of them is called the

23:52

schema registry and it allows anyone to register any type of attestation that might want to be made so for example there there would be a schema for voting a schema for a testing to whether you trust someone a schema for testing whether you like someone a schema for testing to whether a smart contract has been audited Etc and then these are these are types of attestations attestation form factors yeah so it's it's the form fact essentially it's a form factor registry for attestations and then you have the attestation Ledger smart contract which

24:25

just has a ledger of attestations each referencing a particular schema so like you know you you have it you want to make an attestation you have to first reference a particular schema because like what is this attestation about and what is this data structure and so the schema describes like exactly what pieces of data are in there so maybe if I wanted to create like a like an off chain ID card maybe I'd have like a name field I'd have a birthday field and whatever relevant fields and then you can attest with it and anyone can create whatever kind they want and every schema

24:56

gets its own unique identifier what's great about that is when you're testing about a particular schema anyone can know like oh this is this schema this is the not decision from this schema it gives its own category and anyone can essentially attest uh with the same schema as long as it's not protected so schemas can actually also so optionally have a smart contract associated with them and essentially anytime an attestation happens of that schema it'll run through the smart contract and the smart contract can can prevent

25:27

attestations from happening so say for example you wanted to have like an allow list you can block people who are not in the list you can make a payment happen happen so say imagine you created like an oracle schema and anytime someone attests to a particular truth and they're inside of this some particular allow list they get paid out automatically so you can do you can do interesting things like this and just with with these two base Primitives that that's that's that's the whole on-chain component so with these smart because of these smart contracts any smart contract

25:58

any evm based smart contract with EAS deployed can easily verify any attestation and validate it and then also because we we understand that actually most likely over 90 percent of attestations that people will make will probably be off chain is like probably not to stations things between between friends uh there's so many private things that we we don't want to put on chain uh and so what we created is this off-chain attestation

26:29

protocol which uses eip's uh eip712 uh to be able to sign in using your using your wallet uh you're signing off chain signatures that still follow the whole EAS format and standard what's cool about these off-chain attestations is they're completely portable you can pass them from peer-to-peer you can keep them private uh inside our inside our UI you can actually it generates a QR code for every attestation and the QR code as the entire attestation and the signature

26:59

encoded inside of it what's cool about that is you can easily pass this anybody could just scan your address station and it goes from your phone directly to their phone without ever living on a server or optionally you can put an off-chain attestation on a server and then anyone can verify it but what's cool here is it's completely gasless it doesn't cost any money to make and anybody can verify them and then even additionally time stamp or revoke them on chain even after the fact and and one one key thing uh with with that decisions is that they don't always have

27:29

a recipient or someone on the other end like you don't always have to say something about someone else you could be self-attesting more or less so imagine uh bankless had you know bankless study if they wanted to attest to the authenticity of this episode you could generate a hash of the episode and a test that you can that bankless actually produced this hash but you're just it doesn't have to be about another subject the power is that this known entity is signing some sort of structured piece of data at this time so that this was great and I think a lot

28:00

of people will start to have their imaginations um start to go now and they'll start to see this like World open up and just to maybe double down on some points that that y'all made specifically about the the form factor of attestations maybe to put this into the uh Trad world or the the world that we currently have like different attestations come in different form factors that that we already know of right like Stephen your story for example your birth record has is an annotation of your date of birth might actually be the originating document that a test is attest to your your name

28:31

too right um maybe a different like a uh your University diploma a diploma is another form factor for another attestation right um maybe your credit score is an attestation another type of form factor for some Financial Financial related primitive and so the out of stations uh the the EAS that has all these different um form factors for attestations or trying to mimic this world of there's a very different needs of attestations in various different form factors and all

29:03

of these things are are various standards that people are proposing saying hey all the other form factors that that have that already exist aren't servicing the needs of my kind of attestation so I'm going to promote I'm going to advocate for this new type of form factor and I'm going to submit it and merge it to the EAS system and all of a sudden that form factor gets gets uploaded and maybe there's a network effect that grows around that and then and then also you guys said that you will you can also put a smart contract logic into one of these things and I'm sure that just opens up a brand new

29:34

world of of you know territory that we could start to play in just because now we're starting to do some some crypto native stuff uh as well and then the other thing I wanted to just bring attention to is like the off chain component especially like only so many attestations actually need to become transactions like actually we're not really talking about blockchain or cryptocurrency very much at all here we're mostly just talking about private keys and private key signatures and so whether or not they actually make it onto the data of an annotation actually makes it on chain actually is not really

30:05

the focal point of a conversation like this right it actually is like hey all we really need are these private keys and these form factors for consumption that's kind of how I would summarize um the the last little bit of conversation Bryce is there anything you want to add to that yeah I think on the the web three side like the crypto native side the reason why we want to put something on chain is so a smart contract can interact with it right and maybe greater transparency for especially in decentralized communities where you might want like the governance of the community more transparent like how funds are being distributed in this very

30:36

decentralized World putting things more on chain makes more sense but there are a ton of like normal offline use cases that you just need to prove the authenticity of a signature so it really just depends on like the goals of of the use case but they both uh they both have value I want to be clear so you said there was kind of two smart contract Registries like one for the schemas and one for the for the individual either attestations themselves so the schemas that David was describing that's completely permissionless right so like uh anybody

David Hoffman

1490 posts

Co-owner at Bankless. Optimistic storyteller of frontier technology.

A huge thanks to our Friends & Sponsors
No Responses