Interviews

Evin McMullen: Verifiable Credentials in the Metaverse

Zack Jones

·

·

3 min read

Today’s guest is Evin McMullen, co-founder and CEO of Disco.xyz.
We start and end this episode with Evin framing identity as the coolest, most interesting thing people should be working on. She paints such a compelling picture in language that’s so accessible, and she shares tips on how the rest of us can level up our messaging to attract more users as well.
We break down Disco’s product and the origin of their term of choice—the “data backpack”. We go into some of the choices they made in their journey, including how NFTs and verifiable credentials relate in web3, and how they’ve tackled the 3-sided cold-start problem most IDtech businesses face. We also spent some time talking about the factors that make now such a compelling moment in time for digital identity and IDtech product builders.
Evin is easily one of the most fun people in the digital identity world. She has such a way of taking complex things and turning them into snack-able bits of content. If you don’t come out of this episode with a new pithy way to describe digital identity, you should probably go back and listen again because there are so many useful takeaways.
To get your very first data backpack, visit app.disco.xyz. Learn more about Disco at disco.xyz, and follow Disco on Twitter @discxoxyz. Follow Evin on Twitter at @provenauthority. And feel free to join Disco’s Discord community.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the ID tech products of tomorrow. I’m Riley Hughes, co-founder and CEO of Trinsic, and we build infrastructure for launching awesome identity products. Today’s guest is Evin McMullen, co-founder and CEO of Disco.xyz. We start and end this episode with Evin framing identity as the coolest and most interesting thing that people should be working on. She paints such a compelling picture in language that’s so accessible, and she shares tips on how the rest of us can level up our messaging to attract more users as well. We break down Disco’s product and the origin of their term of choice, the data backpack. We go into some of the choices they made in their journey, including how NFTs and verifiable credentials relate in Web3, and how they’ve tackled the three-sided cold start problem that most ID tech businesses face. We also spent some time talking about the factors that make now such a compelling moment in time for digital identity and ID tech product builders.

Riley Hughes: Evin is easily one of the most fun people in the digital identity world. She has such a way of taking complex things and turning them into snackable bits of content. So if you don’t come out of this episode with a new pithy way to describe digital identity, then you should probably go back and listen again, because there are so many useful takeaways in this episode. With that, I hope you enjoy my conversation with Evin. I’m here with Evin McMullen, co-founder and CEO of Disco.xyz.

Evin McMullen: Thank you so much for having me today. It’s another beautiful day in the metaverse, and I’m really excited for us to talk about so many different facets of identity.

Riley Hughes: All right. Well, my first question for you is a fun one. I’ve heard you say that nobody wakes up with dreams of logging in. I wanted to ask you, what do people dream of, and how is Disco going to help people achieve their dreams?

Evin McMullen: If we were to ask a random selection of our friends and family what they would do with a totally free Saturday and all the time and resources in the world, what they probably would not suggest is that they would like to authenticate into apps. Rather, they probably want to be able to spend time with the people they care about, to be able to do the activities they enjoy, to spend as little time as possible filling out forms and waiting in lines, and rather just get on with their adventures and be able to pursue their personal goals and intellectual objectives in whatever way they desire. That really is the goal with Disco. How can we diminish the labor of onboarding, of getting set up, and how can we help people more swiftly get off of the screen and into their adventures?

Riley Hughes: That’s great. So how did you end up working on this problem?

Evin McMullen: The way that I think about how we express ourselves in digital space started quite a long time ago. When I was a little kid, I grew up watching TV shows like The Jetsons that are cartoons about families in the future that have robot sidekicks and automated experiences. Later on, you know, when I was in school, I learned about the ability to create identities that could transact with each other without having to ask for permission on networks like Bitcoin. From there, my career kind of wound through a variety of human-centered design practices, from content to connected hardware like toothbrushes and cars to connected software. And all the while, I realized that many of the systems we were building to improve people’s lives or introduce new technologies very rarely took into account what was best for them holistically as people. Often, we were trying to sell more cars, sell more brush heads, to optimize business operations and create valuable data from individuals that could then be sold or utilized for display ads.

Evin McMullen: But one element that seemed to be missing from many of these practices was how could we minimize the risk and harm that we brought to the individuals in these systems, and how could we help them use data in a verifiable and reusable form so that they didn’t have to fill out a form every time they started a new app, and they were able to carry parts of themselves in a consent-first, selectively shared form so that they could personalize more experiences than in a single app where, you know, most of my work tended to be focused at a given time. So what’s really exciting for me about decentralized identity and the technologies that we work on is the ability to enable that future, for us to own and control our expression so that we can show up in any digital or physical environment and enjoy a personalized experience based on the parts of ourselves that we choose to share. So I’m particularly stoked that now we have a base layer of technologies and new primitives, key pairs to control them, that make this futuristic, often inconceivable future something well within our grasp now.

Riley Hughes: Yeah. Can you imagine an episode of the Jetsons or something where they get out of their flying car and they end up spending eight minutes on some, like, onboarding form? I like to say that clearly the future of identity is going to be better than it is now, far better. And what do we need to do today to get to that future? I wonder, how do you think about that as you’re starting Disco, you’re looking at the potential future and trying to help people diminish the labor of their onboarding into all these different products and services that they want to do. Where do you start?

Evin McMullen: Our vision for Disco is a new way to introduce yourself, so that when you show up in any digital or physical environment, you are able to provide enough information to personalize that experience without having to manually check a bunch of boxes, fill out a bunch of forms, and specify in each specific interaction. So in the crypto space, for example, with our wallets, we’re able to carry tokens from one app to another. Today in the Web2 environment, we have a similar experience with cookies, although we are not sort of intentionally aware of how that data is collected or used, although it does inform our experiences. So at Disco today, we are a bring-your-own Ethereum-compatible keys web app, so we are able to bootstrap new abilities. onto the wallet that you already have so that you can issue, request, disclose, and manage off-chain statements, off-chain credentials, with the same keys that you use on-chain.

Evin McMullen: So what we are doing at Disco right now is extending the ability of existing key pairs, turning wallets into what we call backpacks, so that just like you can throw your physical wallet into your real backpack, carry your financial and other assets that you need with you from one space to another, we’re enabling the ability to do so in digital space and carrying that with you into physical space in a manner that you own and control that’s set up to lead us into legally compliant ways to handle our own data.

Riley Hughes: Awesome. Yeah, I love how there’s a few categories of software that are as boring as identity, and, you know, the way you talk about this space makes it sound exciting and fun. So great job on that. I think you’ve brought a lot of people into this space because of that. Where did the term data backpack come from?

Evin McMullen: So as with all things, we build on the shoulders of giants. So very much appreciate that some of our memes have resonated with you, and we’re very excited that we’re able to use language that connects with many others as well. So the origin of data backpacks actually came from some tweets that had been sent by an investor, Fred Ehrsam, who is known for his work at Paradigm, and he’s an incredibly thoughtful and creative leader in, you know, the investment and technology space. However, he had noted on one occasion that Web3 wallets, crypto wallets, are like bottomless backpacks of data about you. And I kind of took issue with that perspective. A silly movie that I like to reference sometimes when we talk about this is the movie Fight Club, where there’s a line in the film where one of the characters says, You are not your job. You are not the car you drive. You are not the contents of your wallet. And I think it’s important for us to remember that as human beings, we are not the contents of our wallets.

Evin McMullen: You are the multifaceted, experienced, thoughtful, creative friend Riley and colleague who I have in the identity ecosystem. You’re not just a pile of tokens. You’re not just a pile of money or financial assets. You are a whole person with experiences and preferences and traits. And right now, if we only utilize public financial immutable data as a way to express ourselves, which is what blockchains are optimized for, then we’re not going to be able to bring our whole selves to the table to coordinate interesting things that rely upon our expertise or accomplishments, the trust that we’ve accrued in different environments. So for us, data backpacks are a symbol of the way that we should look at our own digital adventures, something that is self-directed, self-owned, and self-contained. We see backpacks as a high-consent evolution of self-sovereignty that we learned through managing crypto assets in the Web3 space.

Riley Hughes: I agree that it resonates really well. How does it differ technically from, like, a crypto wallet or an identity wallet? Things like what the Open Wallet Foundation at the Linux Foundation are working on, for example.

Evin McMullen: That’s a great question. So at Disco, we think about the atomic unit of our connected future and our connected present not as a wallet address or an email address, but rather as a human being. That’s actually why we are called Disco, because we believe that you are the multifaceted center of the party, and you should reflect your data and your identity to the world however you decide. Just like a disco ball, you have many facets and many names that you go by: your email address, your Ethereum address. Similarly, a disco ball has many different mirrors that reflect different parts of itself and can show up differently depending on how the light hits it, how people see it. And so, when we think about the interplay between on- and off-chain data and our ability to bootstrap on top of the existing coordination networks that already exist in Web3, that’s really the sweet spot that Disco unlocks.

Evin McMullen: So to start, we bootstrap on top of existing key pairs to extend those capabilities using infrastructure that people already have at home today, but allowing them to enjoy new superpowers, new ways of interacting, new types of data to create and exchange. We’re particularly excited to bring the best practices from the Web2 space of identity and the long history of research and development from those such as the W3C, the Decentralized Identity Foundation, the Open Wallet Foundation. And so we see a unique opportunity to bridge the well-distributed key pairs of Web3 with the established identity expertise that already exists in many of these circles. And so, as that bridge between the two environments, we have an opportunity to bring enthusiasm, demand for credentials and utility, plenty of use cases on the crypto side, and then our ability to bring in primitives that work with the existing infrastructure and bootstrap onto what’s already there just makes that process even more transparent and accessible for builders already excited about this opportunity.

Riley Hughes: So do you see a future where most people have a Disco-provided data backpack, or do you think that there will be lots of data backpacks, potentially dozens, or for different facets of people’s lives or different use cases provided by a number of different companies?

Evin McMullen: So the phrase data backpack is actually trademarked and owned by Disco. And so in the future, we definitely think that, you know, the concept of being able to own and carry and control and manage our self-expression should be commonplace. And hopefully there are many different forms in which this can work its way into our experience that we haven’t even discovered yet. However, to start, our objective is to make this experience as simple and easy for individuals, organizations, and builders as possible. In the future, the things we like to say at Disco is that designers will inherit the metaverse, meaning that in the future. when many applications rely on shared backends, it is the design and utility that they bring their users and their communities that will set them apart. So our hope with Disco is that we can compete on excellence of experience, and that we can utilize open standards in ways that are uniquely well suited to our partners’ needs, so that there will be many different manners in which you can handle data.

Evin McMullen: But our objective is to provide the one that is best suited to the needs of our partners and the communities that they serve. We definitely think there’s room for a lot of healthy competition and coopetition, if you will. And one thing that we’ve seen in the last year is that many have joined us in this rallying cry for self-sovereign data. Dozens of companies have sprouted up, sort of in the cloud of glitter left by Disco, and have joined us in this particular effort, which is really wonderful to see.

Riley Hughes: What are some things maybe that you think other marketers in our space could learn from the successes that you’ve had that would help to cast an even bigger tent and help the space grow even faster?

Evin McMullen: I really appreciate that question because Disco does not have any formal marketing or PR. And so we’re especially grateful that, you know, our language has resonated and reached others. And what I would recommend to other builders and builders and marketers of all stripes to meet people where they are. It is important for us to meet our communities of builders and users in the first step in their journey, not the first step in our product’s user journey. And so using language that references environments that people already know, trust cues they are already familiar with, allow us to welcome them into these new spaces. We are all digital immigrants when it comes to identity technology. None of us was born into a mature system utilizing the primitives that we have now. And so if we are all digital immigrants, we must use trust cues from the places we already understand.

Evin McMullen: And so if we borrow language from the places we already hang out and we use it in new ways, we can help guide more people into this new plane of being in a manner where they feel confident and they feel trust in the systems they’re using.

Riley Hughes: Cool. Well, I want to shift gears a little bit. You mentioned Disco’s objective is to be the best experience for the people that you serve and the use cases that you are targeting. Could you speak a little more to that? Who are the people today who have data backpacks and what do they use them for?

Evin McMullen: We have started off building in the Ethereum-compatible ecosystem, so communities of individuals and entities that utilize Ethereum-compatible public keys as their method of coordinating, whether allocating treasuries, pooling capital, or buying JPEGs together. And so our ability to use the existing wallets and key pairs that they already have to issue, request, disclose, and manage data that can expire, data that is private by default, that can contain many different types of expression, not just public financial expression, our ability to extend what they can do together skyrockets pretty significantly. The most popular credential, the most popular onboarding reason that is asked of Disco right now is membership credentials. So often leaders of organizations or groups would like to issue membership proofs to their community that can be used for access to physical spaces, GitHub repositories, chat channels like Telegram and Discord, Google Documents, even e-commerce discounts.

Evin McMullen: In the same way that a physical membership card can afford you privileges in multiple spaces, so too are credentials a wonderful way to deliver that capability. Now, beyond membership credentials, we also have a lot of popularity for peer-to-peer social credentials. And so things like GMs that are like Facebook-style pokes that allow people to send greetings to one another in the form of exchanging credentials. They actually started off as just an onboarding tactic to help people feel comfortable with the UX of creating and sending digital assets. But people became so excited by collecting these credentials that they began taking screenshots of them and posting them on Twitter to flex on each other. That’s why we built out the GM leaderboard, where there’s now a more official place where people can compare their GMs and are able to see the streaks of how many days in a row they’ve been exchanging them, et cetera.

Evin McMullen: And we’re building out this tool as a template for our community to create leaderboards based on any credential or combination that they would like, and also to be able to take leaderboard ranks and use those to weight votes and other methods of governance. So right now with Disco, data backpacks shortcut onboarding and make coordination even easier in those places where we’re using keys as the basis of our identity.

Riley Hughes: It’s cool how you’ve gamified the approach of getting credentials and made it fun. I’ve seen a lot of proof of attendance NFTs to gate access to communities, for example. Is your approach to almost say verifiable credentials are a better way to do that, or do you think that they will live side by side where each is optimized for something different, or how do you see that comparison?

Evin McMullen: To borrow a phrase from some of our friends in DeFi, Disco is the yin to the blockchain’s yang. We are able to complement what public blockchain or, you know, ledger-based tokens are really good at with capabilities that they’re not very good at. So tokens such as NFTs are public, immutable, largely transferable, and they’re bound to a specific underlying protocol. And so, if your community coordination requires 24/7 access, data availability for that particular annotation on your public key, if you want that asset to be transferable and public and persistent so it’s accessible for everyone on Earth and in space with an internet connection for all time, then an NFT is actually going to be a great solution.

Evin McMullen: However, if your community wants to allow its members to first consent before they publicly disclose their membership, if you would like for that credential or that membership ability to be seasonal or expire at a certain period of time, or in the future if you would like the ability to revoke it so it’s a little bit more ephemeral, if that membership credential is valuable to be used in more than one protocol-based ecosystem, or you might want to relate it to multiple different addresses, then a credential might offer a superior solution. And so we’ve found at Disco that frequently, especially when it comes to proving your role in an organization or proofs of your non-financial work, such as attending a Twitter Space or contributing to the newsletter, that these particular types of actions are often best described with a proof that is not transferable, that’s not public by default, that isn’t available with the same persistence and publicity.

Evin McMullen: And sort of last thing that we take into account is, depending on what the information is that you want to encompass, it may or may not be safe or legal to put it on a public blockchain. So, for example, if it contains personally identifiable information such as your name or your home address, then it’s not going to be safe or legal or appropriate to put on-chain. So Disco is excited about a street legal way for Web3 to incorporate all of the data we need to build a better future.

Riley Hughes: I was going to say, feels like the requirements that you kind of have outlined make a lot of sense. It also seems like there are cases where there may be room to be more outspoken about when it is safe or ethical to use a public ledger versus not. I guess, how do you balance the big tent and the open approach with a pretty opinionated stance on when verifiable credentials are definitely a better choice for the end user, even if that is maybe not the optimal choice for the organization who is kind of issuing or verifying it?

Evin McMullen: We’re in a fascinating cultural and historical moment when it comes to personal data. In the United States, personal data, data that we create when we interact with applications, is treated as a business asset of the app where it was made. Whereas other places, like Europe and even some states in the United States, treat data as a right of the body, as the dignified work product of the person who created it. And so there is a funny evolution going on in terms of how data gets treated legally and therefore what the rights and responsibilities of builders are when we touch that data or when we invite people to bring it into our app environments. So one interesting challenge is that public blockchains are equal opportunity surveillance platforms. They are publicly accessible open APIs. Therefore, anything that we publish on a public blockchain, we must assume that everyone on Earth and in space, including Mark Zuckerberg and all of the FAANG companies, are readily accessing and utilizing this data without need to sign a license or pay for it or store it or insure it or protect it.

Evin McMullen: And so. It is actually that cost of managing data that is a really great wingman for us right now. So laws like GDPR and CCPA make it increasingly expensive for businesses to store personal data about their users. Indeed, there are some professional sports teams that have lost more than half of their mailing list because they were being stored in a legally non-compliant way. The more that you, as an individual, are able to bring your personal data to an app, use it while you’re there, and take it with you when you leave, that means that business does not have to rent a warehouse and put servers in it and insure those servers and protect them, pay for the electricity, make sure that there is no leak in the ceiling. If they’re operating crypto nodes, you know, ensuring that they’re updating the client and, you know, maintaining security.

Evin McMullen: And so there’s quite a lot of cost that goes into hosting and creating a home for data for your users, especially when you need to be able to comb through it to comply with these laws that require you to delete certain records or share with other organizations. Of course, all enterprises wish that they could see inside of our heads, but the data privacy laws and consumer protection laws that exist prevent this level of invasion. And so it’s up to us as builders to make sure that we are minimizing risk and harm to the parties who use our tools and to remain in the lines legally when we know that we are touching data that is protected.

Riley Hughes: Great answer. There’s just such a proliferation right now of ID tech companies being created, and that’s sort of part of the reason for the podcast here, and that’s why we’re excited to have you here. I want to talk a little bit more about the factors of this moment in time, but first I want to kind of close the loop on the Disco product. A lot of people in our industry, in an effort to generate revenue and create sustainable businesses, target organizations who intend on issuing identity attributes or verifying those things, because businesses generally are the ones who have budget, who a lot of times feel the pain of needing to onboard users, and the current systems of onboarding people are painful, and maybe they can minimize some of that a little bit. And so they go the kind of B2B route, and the products that the people use are kind of an afterthought or a means to the end of approaching the business.

Riley Hughes: On the other hand, I think an approach that you’ve taken that’s very cool is that it feels like Disco is built around the individual, and you’ve mentioned this a couple times already, but it feels like you’re taking a much more bottoms-up approach to your distribution of data backpack. backpacks out into the world. How have you thought about the trade-off there or the approach there, and how have you landed on the approach that you have?

Evin McMullen: The funny thing about organizations and governments and enterprises is that they’re all made up of people. As I mentioned, at Disco, we believe the atomic unit of the future and of connected technology is the human being. And so we build experiences around the needs of those individual human beings, whether they are developers and builders, organizational leaders who might not be technical, or individuals hoping to carry their data from one space to another. We see the growth from serving individuals to organizations of increasing sizes, enterprises, and governments as a sequence of events, a series of composable Lego blocks, if you will, each of which requires slightly more complexity, privacy, security, and scale than the last. And so with Disco, our objective is to not have a three- to n-sided cold start problem to begin with. And that’s really what we tackle when we talk about verifiable data. We need parties that are issuing these signed attestations, the issuers. We need our data backpack owners to take custody of these statements and carry them to other apps.

Evin McMullen: And then on the third side of that triangle, we need our verifiers or relying parties whose apps or services intake, validate these credentials, and utilize them to personalize experiences. This can be really challenging to bootstrap a three-sided cold start problem, and so our thought was, let us identify the places where these three parties already coordinate, where they already rely upon one another, but they are starved for the data that they need to exchange to really unlock the types of coordination they seek. And that is exactly what we found in the Ethereum ecosystem in the Web3 space, where many groups of individuals coordinate based on key pairs, but lack an identity layer sufficient account abstraction and contextual data to coordinate trust-minimized interactions beyond pooling capital. And so we are very excited about the extent to which these technologies have broad applicability, but we must be ruthlessly prioritized in how we move forward.

Evin McMullen: We’ve seen many organizations overlook the switching costs and complexity of an enterprise or large-scale entity moving onto a new decentralized technology, especially for identity. So our goal is to begin in those places where the switching costs are low to adopt these technologies, to prove out the value flows that make sense in the places where they are anchored, and then to continually scale with the sensitivity and robustness of our infrastructure and the data that we can handle, but all the time making sure that we keep the switching costs as low as possible.

Riley Hughes: When you say switching costs, you’re referring to the switching costs of users going between systems or of—

Evin McMullen: So we think about the switching costs of you as an individual backpack owner moving from one app to another. How might we diminish the friction that you experience when you go to app number two and app number three by autofilling some of your preferences and experiences? But then also, how can we diminish the switching costs of an app or service adopting verifiable credentials, integrating the ability to read your data backpack to rely upon your credentials, or even to issue some of their own? And so we found especially in enterprise environments where their endpoints are not necessarily set up to manage keys that can sign in this way, or their systems are not intended for access control using JSON blobs rather than some other method such as a physical card, that is the sort of enterprise or larger-level switching costs that we are able to work around by starting off in communities where we already have all the infrastructure required to make use of credentials such as Ethereum-compatible wallets.

Riley Hughes: I see. That makes sense. I think one objection, or I don’t know if you can call it a critique, or maybe it’s just an adoption barrier that I’ve seen and encountered, is that some organizations sort of view the onboarding friction that is like KYC, etc., as a bit of a moat. It’s sort of the classic, why would my bank want to make it easier for me to go bank at another bank if they sort of gave me a reusable credential? Do you see anything like that in the communities that you’re operating in, or asked another way, are switching costs ever a negative in your ability to get your product adopted, or have you found a way to flip that into a positive?

Evin McMullen: I can imagine that if Mark Zuckerberg and I sat down over a cup of coffee to discuss this, he would certainly have some views on the moat of specific types of data and traits and why managing the distribution of that access could be valuable. However, one thing that I’ve seen that is perhaps a departure from our more traditional Web2 data moats is the desire for organizations, even at an enterprise level, to allow their users or community members to make use of their participation or membership proofs elsewhere, so that they can extend the utility of being part of that community into far-flung spaces that they’re not actually integrated in or they don’t rely upon every day. So allowing others to build composable experiences on the qualifications of your community without asking you is one of the native benefits of Web3, but also allows you to get a lot more mileage out of a single credential than a single entity is able to provide.

Evin McMullen: So it’s the promise of end user network effects that make things like portable KYC credentials, proofs of compliance, something that is increasingly palatable to enterprises that otherwise would want to keep that to themselves.

Riley Hughes: Yeah, very cool. One other thing that you’d mentioned that I think is a golden nugget that I’d love to put a magnifying glass on for just a moment is that you mentioned the three-sided cold start problem, and the approach you took was to find a place where the three parties were already coordinating. You didn’t mention your background at ConsenSys with Serto and some of the other projects you’ve been a part of. but I know that you’ve been thinking about this, including from an enterprise perspective and all of that, for quite some time. And so I think that that insight is really powerful. Could you expand on what does it mean to find a place where the issuer, holder, verifier of the kind of verifiable credential triangle are all already coordinating? What does that look like, and how might other ID tech builders pattern match to find that in their own ecosystems?

Evin McMullen: When we contemplate the issuer-holder-verifier triumvirate, often we think about sort of a hypothetical ability to coordinate, maybe three parties that don’t yet talk to each other or don’t talk to each other in a very effective manner or don’t talk to each other about this specific topic. One of the challenges that I found, especially in the enterprise space, is that when those three parties are not set up to exchange data in a signed form, let’s say W3C compliant verifiable credential schema form, then the switching costs of getting them all set up to be able to communicate in this way can be very arduous, especially when it comes to key management, on-premise hardware security modules, et cetera. There’s a lot of moving pieces there. And so what we started to look for with Disco when we were kind of contemplating how can we get around this lack of infrastructure was identifying where the switching cost is the lowest. What type of people or organizations or builders would have to do the least work to be able to sign a JSON blob?

Evin McMullen: Ah, we know it’s the people who already have keys, who are already making signatures, who already use signatures in their common parlance. Additionally, we were trying to identify, you know, where are there groups of people trying to coordinate who might not have full data about one another, who might need to rely on recommendations or attestations, some kind of trust that’s observed by other parties in their community. But really, the most important thing, sort of the anchoring point for us was observing where are the switching costs the lowest. What group of people should be able to sign an attestation, but haven’t been given the tools to do so yet, though they hold keys, they’re just not being implemented in this way.

Riley Hughes: That makes sense. Thanks a lot. One area that I think could be really interesting to explore with you, Evin, is that the Web3 world is a bit of its own ecosystem, and the more I’ve dove into it, the more I see why people refer to it as the metaverse, because it’s got its own currency, it’s got its own native assets, it’s got its own way of building community and coordinating. And on the other hand, in the real world, we all also have physical-world lives where we’re touching atoms and, you know, moving things around physically and moving ourselves around physically. And it seems like these two worlds are right now a little bit distinct. And yet there could be some really interesting opportunities to take things from one of these worlds into the other. Do you see this distinction the same way that I do? And if so, how do you see Disco helping to bridge these two worlds and create new opportunities for people?

Evin McMullen: I don’t really see it as Web2 and Web3, but rather we’ve got sort of the internet, and then there’s a small group of people building on top of the internet who are very zealous about the additional technology that they bring to the table. And they’ve succeeded where PGP failed because they were able to distribute cryptographic key material to millions of people. And the reason they were able to succeed is that those keys had money on them. And part of the reason that such intensity went into building the core infrastructure and, you know, early app layers of these technologies is that code, like Solidity, allows engineers to pay themselves. And so we have new kinds of incentive systems that are already baked in from the ground up. One interesting challenge and opportunity with the so-called Web3 space, or the world unlocked by private keys and public ledgers, is that there’s a pretty short memory in that community.

Evin McMullen: Very few people have spent multi-decade careers working on cryptocurrencies, largely because, you know, until 2008 or so, there weren’t really a lot that were popularized and, you know, gave the basis for people to build around. And so when we think about Web3 and sort of the builder ecosystem there, very few people are familiar with key pairs and their origin. Very few individuals are familiar with laws like COPPA that govern child online privacy protection, distribution of information about minors, or control access to content with things like tobacco or alcohol. Very few builders are aware that laws that govern data beyond securities laws even apply to open APIs. And so I think there’s a bit of a disparity in terms of an understanding of the legal context and an understanding of the historical technology upon which many of these networks are built. What’s particularly hilarious to me about this moment is that in Web3, we have millions of people with key pairs desperately looking for an identity solution.

Evin McMullen: In the self-sovereign identity space, we have an identity solution, technical primitives that bootstrap onto existing key pairs, looking for a community where it might be adopted. And rather than more effectively communicating between the two, instead we see this bizarre proliferation of primitives unfit for their jobs being used to encompass data best suited for credentials, largely because a lot of people building those solutions are simply not aware that W3C has provided us with primitives well suited to their needs. So there is an education challenge. There is a communication issue. Often many in, you would come from the more academic and identity sort of entrenched side with much experience look at the crypto space as a bunch of scammers. And in truth, the net effect of the crypto ecosystem does, in fact, point to quite a lot of crime and bad actors. And so… I think we need more discussion between the builders in Web3 and those in Web2 or who come from the identity space who already have these answers and expertise.

Evin McMullen: I think we need humility from both sides to learn from one another. And I think we need reference implementations to show people what this looks like. For many years, one of the challenges that we faced in the crypto space was giving people an identity solution they could look at with their eyeballs that was not just a hypothetical paper or set of schemas on some far-flung organization’s website. And so the tangible way that Disco makes credentials as easy to see and touch as your regular NFT, we’ve found has been a big unlock in making these tools more palatable to builders that are used to being able to interact with smart contracts and build in a more Web3-native manner.

Riley Hughes: You mentioned a little bit ago that we’re in a moment in time and a moment in history where something’s happening. And I agree, it feels like something is happening. And I’ve been in this arena for five or so years, and even in just the last year or year and a half, it feels like a switch has flipped and the bucket is filling up with water much faster than it was before. Why do you think that is happening? You mentioned kind of distribution of key pairs as one thing that I’ve heard in this conversation already. You’ve also mentioned legal frameworks and regulation as a theme that has been happening recently. Is there anything else that’s happening, you think, or either of those two points that you think is worth maybe expanding on to explain this phenomenon?

Evin McMullen: Absolutely. I think the third element here, the X factor, Is the fact that we have a bunch of people at home who are bored and desperate to interact with others. This is something that we saw in the pandemic in a very extreme form. And as new technologies in Web3 allowed people to coordinate, to gamble, to hang out with each other in new ways, we saw booms of decentralized finance and tokens, even tokens with silly names like, you know, food tokens like Yam Finance. And then we saw this boom of NFTs, the ability to buy and sell and trade and fractionalize JPEGs as a new way to coordinate. And so group gambling became a delightful way for us to spend time and an amusing activity for us to do that helped us feel empowered and helped quite a lot of people make a lot of money. Where we’ve arrived kind of at that curve is that we have millions of people holding key pairs that they understand how to use, managing private keys in a manner they feel confident about. But the market’s down and they are poor and bored.

Evin McMullen: And so we have reached the ceiling of fun and utility that we can coordinate around public financial assets alone. Playing treasury allocation, gambling with friends, and OpenSea JPEG collection management is not really the height of human inspiration and fulfillment. And so if we want to be able to solve problems together, to build products together, to throw parties or write newsletters, to pursue our intellectual and individual goals in a manner that mirrors what we like to do in our free time off the screen, then we need to introduce a new tool set that is better built for those human beings and the things that they’re trying to do. I think that the novelty and broad distribution of cryptographic technologies sets us up perfectly to unleash what those technologies can do. However, if we, as builders, allow the key pairs sitting in millions of homes around the world to go unused, they will become forgotten. They will not be set up for the kind of success that we know we can achieve if we help people understand how to use the tools already in their homes.

Riley Hughes: Great. Evin, anything else we want to expand on?

Evin McMullen: I think it’s important for us to talk about why identity is the most fun thing. At Disco, we believe that there is no greater delight, more joyful pursuit than building out our ability to express ourselves as human beings. Everybody on the planet has an identity. You had one since the day you were born. You are the world’s expert in being Riley. And so for us to build out a system that does not acknowledge every individual human being’s world-class expertise and allow them to use it in a way that is as powerful as it can be, that just seems like a miss. And so if the only thing I know about you is how much money you have, if you’re just a pile of dollar bills or tokens in front of me, we can’t have a lot of fun together. But if I know your favorite color, you know the communities I’m part of, I know what time zone you’re in, you know what seasonal allergies I have, then we could do all sorts of different trust-minimized things together.

Evin McMullen: And so if we want to have fun in the metaverse and the future of technology, if we want to coordinate more than just putting money together and spending it, then we need a type of data that can change and evolve and be legally compliant and encompass all those other traits we need to start this party.

Riley Hughes: Brilliant. Well, I like to end the conversation with the question, Tell me what the future of identity looks like to you, and you just did that. I think in this conversation and plenty of previous ones, mentioned that identity is not a sexy thing, generally speaking. It’s not a sexy category of technology. But I need to, I think, change my ways there. I need to start acknowledging that identity is in fact the sexiest, the coolest, the most exciting thing that any of us could be working on, and really embrace that as a core way that I carry myself throughout the world.

Evin McMullen: Yeah, identity isn’t a sexy thing. Identity is the only thing. No object, person, or party exists in this ecosystem, in this universe, without an identity. Identity also is not the terminus. It is the thing that gets us to the thing. It’s the set of enabling characteristics or traits that shapes every experience we will ever have, every interaction between machines or humans or organizations that will ever exist. And so it is impossible to talk about any form of interaction, cellular, human organization, or otherwise, without identity being the plane around which that happens.

Riley Hughes: Well, that’s, I think, a great place to end. Thanks a lot for joining and sharing so many of your thoughts. Evin, do you have anything to plug? If people want to get a data backpack or if people want to get in touch with you, how should they do that?

Evin McMullen: We are so excited to welcome all of your listeners to the dance floor. So to get your very first data backpack, just visit app.disco.xyz. We recommend best enjoyed on desktop with Chrome and MetaMask. If you would like to share your metaverse dreams with the Disco team, you can always visit us at disco.xyz. You can follow us on Twitter at DiscoXYZ. You can follow me on Twitter at ProvenAuthority. And we are so excited to welcome all of your ideas, your feedback, and ways that we can even build better. Our Discord community is open and hopping, and so we can’t wait to see you on the dance floor.

Riley Hughes: Awesome. Well, thanks for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me on Twitter at Riley P Hughes or to Trinsic at Trinsic underscore ID, and visit Trinsic if you’re interested in building the ID tech products of the future. Subscribe to get new episodes as they drop. Thanks a lot, Evin.

Evin McMullen: Thank you, Riley. See you all in the metaverse.

Zack Jones

Director of Product Partnerships @ Trinsic

Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon