Interviews
Episode 21 – Phil Windley – Identity Metasystems and Lessons from Building the Sovrin Foundation

Zack Jones
·
·
6 min read

In this episode we talk with Phil Windley, Sr. Software Development Manager at AWS, Cofounder of IIW, former Chair of Sovrin Foundation. We talked about his experience building and leading the Sovrin Foundation, which at one point was almost synonymous with the term self-sovereign identity. It was set up to be an identity metasystem that would reinvent how identity was done online… and we talk about why it didn’t end up becoming that.
Phil shares lessons from identity systems that got adopted, like the social login metasystem, as well as from things that didn’t get a lot of adoption, like certain identity blockchains and information cards a decade prior. We hope this an interesting episode. We’re glad we got to tell a small part of the Sovrin story as we think a lot of today’s reusable ID projects have their roots in the movement Sovrin started—including Trinsic.
To learn more about Phil you can visit his personal website https://windley.com/ where you’ll find ways to contact him, and buy his new book.
Listen to the full episode on Apple podcasts, Spotify or find all ways to listen at trinsic.id/podcast.
Video timestamps from Phil Windley’s interview
You can watch the full video interview on our YouTube channel, or skip to the timestamps below to find the sections that are most interesting to you.
4:04 – How Phil got involved in the identity space
6:00 – Getting involved with Evernym and the early days of Sovrin
8:03 – The NASCAR problem of OAuth login
9:31 – An introduction to identity metasystems
13:29 – How the social login took off as an identity ecosystem
16:43 – Biggest barriers to adoption of reusable digital identity
19:24 – The physical identity credential metasystem
21:48 – Sovrin’s funding model and the consideration of launching a token
28:30 – Red flags that Phil looks for when evaluating new identity projects
31:06 – The importance of governance in creating a self sovereign identity metasystem
32:40 – Phil’s vision for the future of identity
How to get in touch
Most people listen to the Future of Identity on Apple or Spotify. Our podcast is also now available as a video interview on YouTube. You can find all ways to listen at trinsic.id/podcast.
As always, you can reach out to our host, Riley Hughes, on X (@rileyphughes) or LinkedIn. We love hearing from listeners! See you again in two weeks.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to The Future of Identity, a show that surfaces hard-earned insights needed to succeed in the fast-evolving world of digital identity. On The Future of Identity podcast, we skip the conceptual and theoretical conversations and dive into the tactical lessons learned from people in the trenches taking a product to market. I’m Riley Hughes, co-founder of Trinsic, and we are a reusable identity infrastructure company powering dozens of amazing identity products. Today, we have a special episode where I spoke to Phil Windley about his experience building and leading the Sovrin Foundation, which at one point was almost synonymous with the term self-sovereign identity. It’s a special episode because Sovrin Foundation today is different than what Sovrin Foundation intended to be by this point.
Riley Hughes: Phil has been in the identity space for a very long time and shares his lessons from observing identity systems that got a lot of adoption, like the Social Login Meta System, as he calls it, as well as from things that didn’t get a lot of adoption or live up to the aspirations that they set out to in the beginning, like Sovrin and other identity blockchains, as well as information cards a decade prior. So I hope this is an interesting episode, and I’m glad we got to tell a small part of the Sovrin story, as I think that a lot of today’s reusable ID projects have their roots in the self-sovereign identity movement that Sovrin helped to start, including Trinsic. And now to my conversation with Phil. Phil, welcome.
Phil Windley: Thank you. Good to be here.
Riley Hughes: I’m excited to have this conversation. I don’t know if you know this or we’ve ever talked about it explicitly, but you were basically my first point of contact in the digital identity industry. So after interviewing with you for a job at Sovrin, I went home and spent hours reading your blog and the Sovrin website and white paper. And so first of all, I want to say thank you for what you did for my career and many others.
Phil Windley: You’re welcome. Thank you for being willing to participate in a journey and join us at Sovrin.
Riley Hughes: When I started in the identity industry, I felt being surrounded by people like you and Nathan George and, you know, all the people on the board, Drummond, I felt very in over my head. So I started reading everything I could about identity, including, like, the philosophy of identity. I remember landing on the ship of Theseus, and this is not a philosophy podcast, so we don’t need to go into depth on the ship of Theseus. Look it up if you’re interested. But ironically, I think Sovrin Foundation is actually a really interesting object lesson for the ship of Theseus. Basically, it started off on a certain trajectory and had a certain set of employees who are now all gone, had a certain board of directors, which has now all moved on to new things. It had a certain set of stewards running the network, some of which are still around, but many of which have churned, and there are new stewards now. It’s interesting to see how the network has changed so much, but it’s still resilient. It’s still around.
Riley Hughes: So I want to talk to you because I think the story deserves to be told, both how you helped create such a resilient and anti-fragile network, but also what its initial aspirations were and where it’s ended up relative to those aspirations.
Phil Windley: I think the ship of Theseus is also a good object lesson just for digital identity in general. We keep replacing the technologies, but the overall problem remains the same. I think we keep circling it, getting closer and closer, but yeah, we replace everything over and over again to solve the same problems, and hopefully we’re getting better.
Riley Hughes: Yeah, that’s actually really interesting. I hadn’t thought about it that way, but it’s super true. Maybe it doesn’t remain the same ship if we’re getting better. I don’t know. Yeah, it’s interesting. You’ve obviously seen a lot, even just as your role in the Internet Identity Workshop, having seen information cards and all kinds of different blockchain-based approaches to identity and things like that. You know, if we start from the beginning of Sovrin, what was it that kind of brought you out of the advisory and book writing, the kind of role that you had previously in digital identity into a much more hands-on role with Sovrin? What was it that made you think that the Sovrin approach— was the thing that would finally sort of crack the nut on the ship of Theseus and be the version of the ship that set sail.
Phil Windley: Up until 2016, when we formed Sovrin, my role in digital identity was primarily less opinionated. I definitely had opinions about digital identity and how it ought to work. I mean, after all, I wrote a book in 2005 about it. I, you know, helped found IAW, which the primary goal was just to get people together to talk about it. It’s actually funny because the people who came to the first IAW, we all said that we had something else we wanted to do, but we needed to solve identity in order to do it. And we thought we’d have a couple of sessions, a couple of meetings, wrap it all up, and we could all go off and do our own things. In 2015, self-sovereign identity started to become a thing. I had come to see that the words we use to describe digital identity, user-centric identity, wasn’t a strong enough word. That even though we had built systems like OAuth and OpenID Connect and others, they still weren’t giving users control.
Phil Windley: That’s probably going a little too far because clearly OAuth gives you control over whether you want to share your information or your login credentials from one identity provider with a relying party. But it wasn’t what we were after, especially when we were thinking about the idea of personal clouds and how people have more control over their data. So I was very interested in this idea of self-sovereign identity as maybe something new. There was a company in Utah, Evernym, Jason Law and Timothy Ruff. I had met with them. They talked about what they were doing. It was just kind of run-of-the-mill identity stuff. It wasn’t all that interesting. And then I was reading a news group, and somebody said, Oh, these people in Utah over there were doing self-sovereign identity. So I called them up. We went to lunch. Timothy said, Oh, you’ve got to come to Denver next week. I said, Why would I go to Denver? He says, Oh, we’ve got the credit unions. They’re all on board. So I went to Denver. I took Drummond with me. That’s how Drummond got involved in all of this.
Phil Windley: And sure enough, it was a hotel ballroom full of probably 90 to 100 people from credit unions across the U.S. saying they were interested in self-sovereign identity. I told Timothy that while I thought what he was doing was really interesting, I didn’t think that an identity ecosystem—I didn’t use those words because we didn’t use those words back in that time frame—but I said an identity ecosystem couldn’t be controlled by a single company, especially not a small startup. He agreed. It wasn’t an argument. He had this feeling too. And so we collectively decided that we should form the Sovrin Foundation as a nonprofit. The reason we did a nonprofit is because we believed that was a better model for managing an ecosystem of identity providers that would be governed in a way that helped give people sovereignty over their data. Evernym agreed to donate their technology to the foundation to essentially seed an ecosystem that was bigger than just a single company. That was really the start of it.
Phil Windley: And in the fall of 2016, so I decided that it was time to jump in and do something to make this all happen.
Riley Hughes: When you’re talking about what you’re after with self-sovereign identity as compared to something like an OAuth, from a user perspective, user has some control, the user gives consent and all of that. But from a business perspective, as a relying party, I need to do direct integrations, ask for permission, and get all of that from all of the identity providers that have information about my users that I might be interested in. And so it really— is a model structurally that tends toward centralization or tends toward consolidation, a winner-take-all solution, right? It tends toward, well, Google’s got everybody’s information, so let’s just all integrate Google and call it a day. We don’t need to integrate a variety of sources of data.
Phil Windley: We used to call this the NASCAR problem. People did envision that you would use your own domain. I had OpenID running on windley.com, and I would use it to log in to places like Stack Overflow. But the array of buttons that people had to choose from—you’re right, there was a definite integration problem. Website owners obviously want to make it easy for people, right? Oh, I just click Google or I just click this. But the other issue, too, is who do I trust? Simple example is if I’m using windley.com to log in to Stack Overflow, how does Stack Overflow know that I’m not just letting anybody who wants to be redirected to windley.com, no password or anything, just say, Yeah, they’re Phil at windley.com. There’s no way they know that. So that worked great for places that didn’t necessarily care that much who you were. They just wanted to associate with you with an account so that your comments all showed up or whatever. But it didn’t work where people were concerned about security in any way. So, yeah, it tended to Google, Facebook, Apple, Amazon.
Riley Hughes: On the other hand, when I think back to my time at Sovrin, you tended to talk about Sovrin as an identity meta-system, one of the first things that you had seen that sort of met the laws of identity outlined by Kim Cameron a decade prior. So I wonder if you could speak to that concept of an identity meta-system, if it gets to this notion of an open-loop network as opposed to something that’s very closed down and restricted and bespoke.
Phil Windley: I just finished in 2023 my second book on digital identity, and I feature Kim and his laws prominently at the start of the book, in chapter four. I did that because I wanted to use the laws and the idea of the metasystem to kind of evaluate different identity technologies. I probably didn’t do that as well as I could have, but in the last chapter, I wrap it up by saying right now the world is more or less operating with two identity metasystems. One I call the social login metasystem. So what does that mean? It means that it’s not Google’s identity system, and it’s not Apple’s metasystem or Facebook metasystem. In this case, OpenID Connect is the primary protocol, and so I talk about that and how it matches up with the laws of identity, and actually it does very well. The place where I think it falls down most is in what’s called directed identity in Kim’s laws. We would think of it as peer-to-peer identity because it obviously is based on large identity providers. The other metasystem I talk about, obviously, is the self-sovereign identity metasystem.
Phil Windley: Others might call it the decentralized identity metasystem. The same things make it work. It has protocol. It has technologies behind it. It has standards. It has process that people hopefully, as it matures, come to understand. And that’s one of the challenges, is you’ve got to get people used to the ceremony. Protocols are always a ceremony, and so how well the ceremony functions, especially when people are involved in that, is one of the key factors in the metasystem. The idea of a metasystem is can we build a community in a way that would encourage those kinds of sharings that Would make the system more valuable. Let’s say a bank decided they were going to support OpenID Connect, and in their identity token, they were going to include attributes that had to do with their know your customer, KYC process. There’s nothing stopping them from doing that. Why don’t they? You probably have to talk to a bank to find out, because at the end of the day, it’s really all about verified data. We say identity, but identity, that’s just the word we use for it.
Phil Windley: It’s really about data, about people, and whether or not you can trust the data.
Riley Hughes: So I have a bunch of follow-up questions here that I want to get into. You talk about the self-sovereign identity meta system, but most of my time that I spend is thinking about the question of adoption, because one thing I realized early… on at Sovrin, when I was working there, was that this becomes really valuable once there are lots of people who have wallets with credentials inside them. And of course, lots of businesses would love to accept pre-verified people. But there’s a cold start problem, and before you have one side of the network, it’s challenging to build up the other side of the network. In a picture-perfect verifiable credential meta system, there will be issuers, holders, and verifiers. So it’s really a three-sided cold start problem, which can be tricky. So when I think about this question through the lens of adoption, I see the social login meta system as being emergent, in a sense. It wasn’t like a single entity that set out to create a new meta system and they were going to do it via this protocol or whatever.
Riley Hughes: It’s sort of the social providers had reasons for doing OpenID Connect, and it sort of became an identity meta system over time. When I think about a lot of the self-sovereign identity meta systems, though, adoption has been the challenge. And I guess the question is, can you create a general-purpose meta system from the beginning, or do you need some specific use case or wedge to build out from there?
Phil Windley: I have my own theories about the social login meta system, and I watched it evolve over time. Nobody said, Oh, we’re going to create a social login meta system, but they had a real problem, and that real problem was that people were spending too much time building their own centralized identity systems. People were spending too much time remembering passwords. There were security issues. And so, you know, the technologists said, Oh, let’s build a system for solving that. It didn’t take off. What happened was Web 2.0 was also happening. And some people, also people who attend IIW, came up with another protocol called OAuth. And OAuth was about being able to give authorization to access your data at some webs, usually with an API. People realized, Hey, I could use this for logging in. And so they did. OpenID Connect, which has very little to do with the original OpenID other than that the same people did it and the same foundation is behind it, essentially took OAuth and augmented it in order to create OpenID Connect.
Phil Windley: That meta system evolved, but there was a very real problem that actually drove adoption of something, and that was API access. And contrast to that, at the same time, Kim Cameron was trying to create a meta system around Microsoft’s product called CardSpace. The general idea was InfoCards. That was happening at the same time. That never got off the ground, partly because even though the technology was really good, I used it for some things, Microsoft was seen as too big a player. People worried that Microsoft was controlling the ecosystem. Ecosystems are tough, right? Because of all of these problems. Who is controlling it? Why are they controlling it? Is there a real use case that’s driving it? And in the case of OpenID, the use case was access to APIs.
Riley Hughes: That is really interesting. I was actually just thinking about how at a previous IIW a couple years ago, I had a really long, in-depth conversation with Vittorio about verifiable credentials and the idea of basically standardizing things. But he worked on the information card stuff with Kim Cameron at Microsoft, and one of his learnings was that the emergent… OpenID Connect ecosystem basically was standardized after production implementations and production solutions were already out in the wild. Like it wasn’t like they designed it on a whiteboard, standardized it first, and then built software to comply with the thing that they had envisioned and drove that into production later. It was that people built production solutions to solve their problems, and then they basically took the things that worked well in the wild and standardized them. And then over time, the production implementations complied with the standards and so forth. It’s an interesting question of how these things come to be.
Riley Hughes: And part of the reason for doing this podcast is to try to explore what needs to be true for us to see a world of reusable identity is what the term I like, or self-sovereign identity meta system emerge in the world.
Phil Windley: I have been around and around this question multiple times, and it’s an interesting one. If I had the answer, obviously I would be driving adoption like crazy. But I do think that there are some very real kind of things that get in the way. I’m sure, like me, you have had dozen moments over the last month where you’ve thought, Oh my word, this is so stupid. If only people would use verifiable credentials, we could solve this problem and we wouldn’t have this blah blah blah, whatever it is. Before we started the recording, you had mentioned mobile driver’s license, and I have one. I’ve got it on my phone. And we both had the same experience where I was going through the TSA line and it said, Oh, use your mobile driver’s license here at TSA. I get up to the thing and the guy says, Oh, my station doesn’t have that equipment for doing that. If you want to do that, you’ll have to get back in line and go over to that station. There are already existing solutions for many of the things we would like to use verifiable credentials.
Phil Windley: We are so used to the idea of using credentials in the physical world that it seems antithetical to our digital experience. And I’m partly at fault, I guess is one way to put it, right? Because I built identity systems back in the day. We thought we knew how to do this, right? You just get usernames, you get passwords, and okay, we’re done, right? Solved the problem. We got into this mindset that everything online involves logging in with a username and password, and it’s just a big mindset change to think about. Going to credentials online. And yet, I’m sure you have thought about this too. There are so many offline experiences that we can’t have online because we’re not, I like to use the term, digitally embodied. As individuals, we do not have a place to stand online. Imagine a typical physical experience of meeting a friend at a cafe for lunch. You don’t have to log in to the cafe. You don’t have to have a separate login system in order to get to the menu because it happens to be provided by somebody else. We would just laugh at that experience, right?
Phil Windley: And yet that’s the things that we put up with all the time in the digital world. So there are all kinds of stuff that could be better, but people are just getting around the problem in other ways.
Riley Hughes: Yeah, I was going to ask whether you think there’s maybe a third metasystem of mobile driver’s licenses or even in-person credentials, like the protocols and ceremonies we go through to present.
Phil Windley: Yeah, that’s a great point. Physical credentials. The way digital identity works in the physical world is a metasystem, because people know how it works. I mean, the idea of a metasystem is it’s not a specific system for doing something. It’s a system for building systems, right? So people understand credentials in the physical world. Any business can say, Oh, we want to create a loyalty program. We’re just going to go to a company and get some plastic cards and put numbers on them. So there is a metasystem around how credentials work. You go into the pharmacy and use your driver’s license to prove that you’re over 18 to pick up a prescription. The pharmacy doesn’t have to have permission from the state in order to use the driver’s license. They don’t worry about whether the state’s real because there’s a metasystem around that. And so, yeah, I mean, there is a metasystem there. It’s imperfect. Online degree scams happen because most people don’t know how universities are accredited.
Phil Windley: But there is a process for accrediting universities, and that’s part of the physical identity meta system, right?
Riley Hughes: On this thread of trying to create the self-sovereign identity meta system, if we shift back to the sovereign story, a few months ago there was the OpenAI boardroom drama where they fired the CEO and all of that, and I think that’s an example that is illustrative because although they’ve catapulted into the tech zeitgeist and got 100 million users of ChatGPT basically overnight, they were silently building for eight years or something before any of that happened. And I think, you know, if you ask most people in tech about OpenAI during those eight years, most people wouldn’t know who they are as opposed to today. And OpenAI, like Sovrin, has this really big ambitious vision. OpenAI wanted to create artificial general intelligence. Sovrin wants to create an identity meta system. And to do that takes a lot of resources. And the OpenAI path started as a nonprofit. Sovrin was a nonprofit. OpenAI says, let’s carve out a commercial entity and sell software, sell access to our APIs and our models, and that’s the way we’re going to commercialize this.
Riley Hughes: And by creating a commercial entity, they could then raise capital in instruments that look a lot like equity. On the Sovrin side, though, to capitalize the mission of the foundation was a different approach. You know, as you were thinking about this question, how do we acquire the resources needed to create this massive project that we need? How did you think about capitalizing it and the trade-offs associated and the risks associated, and how did that all go down?
Phil Windley: Like you say, any organization, nonprofits are a special kind of organization in this regard, need— Resources in order to accomplish things. And, you know, Sovrin Foundation was trying to build a meta system, which meant that we were trying to sponsor technology. We had employees who were going around and not just evangelizing, although evangelism was a big part of the job, but also working with standards groups and building on open source technology, and that all takes money. Sovrin was a membership organization, a 501(c)(6) in the IRS code, so we charged our members dues, essentially. And those members were, by and large, corporations, because most people don’t really care about what identity system they’re using, right? And so we had a number of cases where we’re just trying to keep all of these different corporate members happy. I felt like it was my responsibility to actually be true to Sovrin’s tagline, which was identity for all. We were trying to build an identity meta system that didn’t just serve the needs of some companies or the U.S. or the developed world.
Phil Windley: We had guardianship task forces. They still do, and there’s some great work there in terms of how can we use this identity technology to improve the lives of people around the world. That created conflict and some strife. At the same time, there was, in the world of blockchains, and Sovrin was built on a distributed ledger, there was the idea of tokens and coins, right? And if you think back to 2018, that was when it was all just getting started, and everybody was just excited about it. Anything like that is always full of people who are scamming. It’s full of people who are dreaming. It’s full of people who are thinking that this is a way to solve problems. We saw this as not just a way of raising money, but we actually thought that there was real need for a payment system that was part of the identity meta system. I still believe that part of the adoption problem is that there are lots of use cases that require payment, and that doing payment external to the identity.
Phil Windley: system, where they’re not in some way linked, that those use cases are simply not done because there’s no way to do payment. Because we were a membership organization with lots of corporate members around the world, we tried to be especially aware of legal requirements. We spent lots of money on legal fees trying to make sure that we were doing everything above the board, complying with FinCEN regulations, complying with U.S. regulatory regulations. We were trying to build something people would trust, and not just people, but companies, right? So, long story short, we probably took too long. We probably pushed it out too far trying to be careful. And this is a lesson for any startup founder. I’m sure you have wrestled with it. Being early is the same as being wrong. Being late is the same as being wrong. And I think we probably missed the window. And so the token never got issued. There were lots of people who were pushing back against the token because they were concerned about all of the scams that were happening in that area.
Phil Windley: And the foundation never got the funding it needed when COVID hit. We were actually in the middle of a token sale, kind of the pre-sale, and we just had to close it down because of the market conditions at the time. And that was, you know, end of that era for the Sovrin Foundation. As you mentioned, it’s gone on. I think they still do some interesting things. I don’t believe they see themselves as building a meta system, not in the same way.
Riley Hughes: One of the lessons that I take away from this is that the way that you’re funded sets the course for the business, right? It’s like certain genies you just can’t put back in the bottle. Certain investors, once they get on your board, there is no divorce procedure. There is no annulment there. It’s just they are now there. And if you think about OpenAI, you can’t put the ChatGPT genie back in the bottle. It’s out there now, and that is a part of their story and forever will be. And likewise, I remember being at the foundation. It’s like the fundraising via token path required some amount of risk because there was not perfect clarity on all regulations and all jurisdictions and all of that. And yet the corporate membership model inherently attracted folks that were allergic to risk, right? Sometimes I wonder about the counterfactual scenarios. I wonder if this would have been different or that would have been different, or if Sovereign would have just said, the hell with it, let’s just launch the token anyway. What would have happened?
Phil Windley: I wish that I had just pushed forward. In the end, the world changes. As founders, we come to an understanding of the world and we say, okay, I’ve got a startup idea. I’m going to push this idea. We fail to look around and say, what has changed? And more than that, we sometimes fail to realize that things are going to change. Obviously, no one could have predicted COVID. And if COVID had happened three months later, the story of Sovrin Foundation might have been very different. But those kinds of things happen. And when they happen, your business might be in a position to take advantage of them, might be in a position where it’s particularly vulnerable. And startups, and Sovereign was definitely a startup, startups are not immune. They’re particularly vulnerable to acts of God because they have very little resources to fall back on. The bank account goes up when you get investment. It goes down depending on when something bad happens, you could be in a bad spot, and that’s the end.
Riley Hughes: It strikes me that in the identity industry, there has been this vision of, as you framed it at the beginning, a user-centric identity or an identity meta-system that puts consumers at the center of their digital lives. This has been in people’s minds for so long, two decades or something. And there are stories like this, ambitious projects that don’t get adopted or don’t meet their lofty ideals all over the place. So I guess I’m curious if you have some kind of pattern recognition that you could share when you become aware of startups or coalitions or efforts, networks, whatever, that are trying to do something like this. What’s your algorithm that you run these projects through to tell you whether the odds of success are reasonable or not?
Phil Windley: I found a great answer to that. That would make a great book, don’t you think?
Riley Hughes: Yeah. Or a great podcast episode.
Phil Windley: Yeah. I mentioned Evernym earlier, and in my interactions with them, and essentially dismissing them at first, because they were a startup who wasn’t really doing anything that was very new. I don’t think that’s necessarily always a bad thing, because I can also think of startups that weren’t necessarily doing something brand new, but they did it better or in a slightly different way. I think it’s easy to dismiss startups that you talk to them for an hour. You might not get a good picture of what’s really special about them. Who are the players is also a big thing. This doesn’t apply to things like startup. It applies to new standards initiatives or somebody trying to jumpstart something. Do they have experience? Because a lot of times people think identity is really easy. There are people who think they have the answer to identity. Their solution is essentially a universal identifier that their company controls, and that’s how they’re going to make billions of dollars. Multi-sided markets are hard anyway. Yeah. Just the idea of universal identifiers, I think, is a red flag for me.
Phil Windley: One of the biggest problems of digital identity is proximity. Just the fact that we’re not by each other. And with AI being able to generate voices and pictures, even videos, it may not even be enough that we have a video of you and I talking. I don’t know if I’m talking to Riley or some chatbot, right? And so that proximity problem is real, and one that we don’t face in the physical world. So those are a couple of red flags. that I look for. Universal identifiers, are they doing something that seems like it’s been solved before and not in a particularly new way?
Riley Hughes: Awesome. Phil, anything else you wanted to cover today or think we should talk about? I wanted to give you a chance to plug your book at the end.
Phil Windley: Yeah. You know, I obviously think it’s good, but it does talk about these issues in some detail, both the technologies involved, but also trying to form opinions about the technologies and what they’re good for. I don’t think there are a lot of bad identity technologies in widespread use. There are some bad identity technologies, but not in widespread use. So it’s really a matter of finding out what they’re good for. Do they solve the problem you’re trying to solve? Are you thinking about your problem as big as you should? I think that there are still plenty of folks interested in building self-sovereign identity metasystems. I believe, like you’ve said, some of it will be emergent, but hopefully we’ll be able to get some governance around them. There’s a new term people are using called acceptance networks. It’s actually a term they’re borrowing from the Financial Services Organization or industry. Acceptance networks are things like Visa, MasterCard, Discover, American Express. They have protocols, technologies, processes, governance, legal agreements. They’re metasystems.
Phil Windley: And there are people who are trying to say, how can we build a metasystem? Because there are real problems of digital identity that are difficult to solve without going back to the idea of the social login metasystem. In the self-sovereign identity metasystem, one of the big differences, I think, has to be for adoption to take place of self-sovereign identity, for it to be sufficiently better than social login metasystem that companies particularly will adopt it, is governance. Because governance solves the very real problem of trust and placing trust with confidence. Trust is always based on risk, and confidence is essentially when you reduce risk, you increase confidence. And so that’s what governance can do. So I’d like to think that we’re still on that road, and I think it’s important for what we’re trying to do.
Riley Hughes: I like to finish by asking what the future of identity looks like to you. After everything you’ve been through, what is the future going to look like that’s different than today?
Phil Windley: I like to imagine a world where people are digitally embodied. In other words, where they have some place—we talk about those being wallets or agents—some piece of software where they control the credentials and other identity data that is important to them, that feels a lot more like the physical world. As we move into a digital future, one with generative AI, as we’ve talked about, I think the idea of digital identity becomes more and more important, and more and more of our lives are going to be intermediated by digital means. Having control of your digital identity, not having it controlled by someone else, I think is critical to having lives that are worth living. I really hope that’s the future. I think the future without that kind of system is very dystopian. And I hope we don’t go there.
Riley Hughes: Cool, Phil. This has been an awesome conversation. Thanks a lot for joining. If people want to connect, or if they want to learn more, get in touch, learn from you, where should they find you?
Phil Windley: I blog at Windley.com. So just my blog is a good place. There’s a contact form on that. I’m happy to have people contact me. Obviously, I’d love people to buy the book and read it. If you’re non-technical, I like to say read the first five chapters and the last chapter, and then fill in the middle as you see the need. But if you’re technical, I think all of it could be interesting.
Riley Hughes: Great. All right. Thanks a lot, Phil. Thanks so much for listening. If you enjoyed this content, please share it with others who will benefit from it. I’ve been getting some great feedback on the podcast recently. And since we don’t do a lot of self-promotion or ads or whatever, sharing the word really is the best way to signal to us that the content is valuable and that we should keep doing it. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me directly on LinkedIn or X at Riley P. Hughes, and visit Trinsic if you’re interested in building the future of identity. You can also visit trinsic.id/podcast to subscribe to new shows, and subscribe to the Future of Identity newsletter, where we’ll share the essential reusable identity news we rely on straight to your inbox.

Zack Jones
Director of Product Partnerships @ Trinsic
Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
