A document with no off switch
A condensed reading of a long article on self-sovereign identity. Instead of walking through its chapters we pull one thread: every credential has somebody who can switch it off. There is exactly one way to strike that person from the picture, and it carries off the ability to fix anything later.
Every credential has an off switch
Ask who stands behind any document that confirms you, and the same answer names whoever may take it back. A state seizes a passport. A company closes an account under rules of its own composition. A domain moves on the decision of a registrar, a registry, a court or an investigation. A verification mark vanishes the day a platform changes policy. Timing and procedure differ; the construction does not. A credential is not an object but somebody's maintained assertion about you, and the moment that party falls silent, what remains in your hand is a picture.
The right to switch an account off is not hidden; it is set out calmly. Google reserves suspension of access and deletion of the account for material or repeated breaches, where the law demands it and where behaviour creates harm or legal risk, promising notice in advance «where reasonably possible». YouTube's formula is a relative of it: access to part of the service or all of it may be ended if conduct is judged dangerous to users, to outsiders or to the company itself. In both texts one side does the judging; the other learns the outcome.
Three episodes where the switch was used
February 2021. Two fathers, one in San Francisco and one in Houston, photographed inflammation on their small children at a clinician's request for a remote consultation. The images travelled to the cloud on their own, an algorithm took them for child abuse material, the company notified law enforcement but not the fathers, and in one case went through the whole archive. Neither the San Francisco review nor the Houston one found an offence. The accounts were still not returned: email, photographs and video were gone, and for one man a phone number as well. Kashmir Hill wrote it up in The New York Times; the EFF published the legal reading in August 2022. A police finding of innocence proved powerless, because it had not been issued by the party holding the switch.
2025, the Meta platforms: the BBC counted tens of thousands of complaints about mistaken bans, more than five hundred people wrote to the newsroom themselves, and a petition about mass shutdowns and the absence of any live human in support collected over 25,000 signatures. Some accounts came back after journalists asked about individual stories, which means the working appeal route was a newsroom, a route almost nobody has. Two more shutdowns involved no fault at all: on 20 April 2023 the blue ticks disappeared from everyone verified on Twitter before the change of ownership and turned into the sign of a subscription costing eight dollars a month on the web in the United States; Google+ closed to ordinary users on 2 April 2019; and Skype was retired on 5 May 2025 with chat and call history left reachable until January 2026.
The complaint goes to the party that pressed the switch
A dispute about a document is settled by its issuer, which follows straight from the same construction. Then arithmetic takes over. Automation makes the decisions because the volume cannot be handled by hand; as many complaints arrive as there were decisions, so they too go to automation; the loop closes and the system checks itself. For scale: Google looks at no more than two appeals on a disabled account, after which it stays disabled and moves to deletion with everything in it. The European Digital Services Act makes platforms explain their decisions, mark the automated ones and set out the routes of appeal, and those explanations accumulate in a public transparency database. The step is real, yet it points inward: the issuer's procedure improves while dependence on the issuer stays exactly where it was.
The industry has admitted the defect and half repaired it
The W3C approved the decentralised identifier standard on 19 July 2022: by its own description such an identifier needs no central issuing authority and travels between service providers. Approval came over formal objections — Google asked to wait for at least three mature «methods», Mozilla argued that practical interoperability had not been demonstrated and that the specification leans on a registry of some fifty such methods. The objections were overruled rather than resolved, and version 1.1, published as a candidate on 5 March 2026, was still a candidate in August. The credential format itself, Verifiable Credentials 2.0, became a Recommendation on 15 May 2025 in seven documents at once, Bitstring Status List 1.0 for revocation among them. The standard does not abolish trust in the issuer but formalises it; the status list even hands part of the old dependence back, since revocation is the issuer's to maintain and you have to go to him again.
The European wallet travels the same road. Regulation 2024/1183 has applied since 20 May 2024 and requires citizens of each of the 27 countries to be offered at least one such wallet; the clock is counted from the implementing acts of late November 2024, and the commonly used arithmetic gives 24 December 2026. Verification there is arranged as a chain of signatures: the document, then the issuer on a national trusted list, then that list inside the LoTL compilation, then the Commission's signature. The state has stopped being the place you send a query to, yet it remains the source of whom to believe. Readiness is uneven: Germany named 2 January 2027, the Netherlands let it be known they will not make it, Malta expects to appear with part of the functions.
How a document that cannot be switched off is put together
The passport itself is ordinary JSON that opens in a notepad. It goes into Arweave once and receives a transaction address 43 characters long; the address serves as link and checksum together, since a different set of bytes would give a different address. Inside sit a name and an alias, a short description and a manifesto, links to Telegram, X and a website, the tier level, the moment of issue to the second, the address of the issuing site and an identity fingerprint. The email is not in the file; its sha256 is.
The reason for that substitution is arithmetic: the record is public and permanent at once, and the pairing is more dangerous than either property apart. An address in the clear will be taken by the first harvester with nowhere to recall it from, and an address is half of a login. The fingerprint still leaves the owner a way to prove the record is his: compute sha256 of his own email, compare 64 characters. Anonymity it does not give — whoever already suspects the address will test the guess by that very method, and an unsalted email hash has long been treated as a pseudonym, and by regulators as personal data. What it does give reliably is different: you cannot write a letter to a hash.
A number like CE-378E447D is likewise assigned by nobody: the first eight characters of the fingerprint are put into upper case. There is nothing to drift — no counter, no lookup table to be lost when a database moves; anyone can recompute the number from the file twenty years from now. Eight hexadecimal characters give on the order of 4.3 billion combinations: enough to read a number out over the phone, not enough to call it unique forever. The document is identified by other things — the 43-character address and the full 64-character fingerprint.
A check the issuer takes no part in
The order runs like this. Open the address on arweave.net and see the source file rather than a styled page. Repeat it on somebody else's gateway — there are hundreds, held by different people in different countries, and a substituted file would simply not be served at that address. Match the date in the field against the block number the network recorded: anything backdated would be visible to all. Compute the sha256 of your own email. For a live document the network answers with the lines block_height 1975726 and number_of_confirmations 130, and the second figure climbs by itself and never goes down.
The symmetry: no revoking means no correcting
There is no «modify» action in the protocol at all; there is «write». A typo in a name, a link to an account that will be abandoned within a year, a manifesto composed at three in the morning, the tier level as of the day of issue — all of it freezes exactly as it entered the network. A new version can be written and then both live side by side. For the same reason an alias is reserved permanently and never returns to circulation even after an account is deleted: ten years on, nobody will tell apart two different people under one name in a permanent record.
Here it collides head-on with the right to be forgotten. Article 17 of the GDPR permits a demand for erasure, and its third paragraph lists when the demand does not carry: defence of legal claims, scientific research and archiving in the public interest, public health, compliance with a legal obligation, freedom of expression. No entry there reads «technically inconvenient for us». Back in its 2018 guidance the CNIL proposed keeping personal data off the chain and delivering erasure by destroying the key; the EDPB in Guidelines 02/2025 — April 2025, with version 2.0 dated 7 July 2026 — is stricter and accepts neither plain text nor encryption nor hashing. The honest framing follows: this is a publication, not a row in a database. Its nearest relative is a book that has gone out in a print run and scattered across libraries, and print runs are not recalled.
What the document does not do
It is not a state document: no agency, bank or university is obliged to look at it, no border is crossed with it and no account is opened. It does not certify that a person is who he claims to be: the record is published on that person's own application, and anyone may put a file bearing somebody else's name into an open network with no issuer involved. What is verifiable is different — that on a given date a record with given fields existed and has not changed since. The revocation built into mature credential schemes is absent on purpose: a trade, not an omission.
The usefulness is narrow and real. A date your own laptop is not answerable for helps in a dispute about who came first, although copyright under the Berne Convention with its 182 parties arises without any record, at the moment a work is created. A link lives longer than platforms: in May 2024 the Pew Research Center measured that by October 2023 a quarter of the pages that had existed between 2013 and 2023 were unreachable, and that 38% of the 2013 pages had gone. The word «forever» needs its caveat too, and the article makes one: payment happens once, the smaller share going to whoever accepts the file and the larger into an endowment, with the calculation resting on an assumption that storage gets cheaper by at least half a percent a year on a two-hundred-year base. That is a bet, not a law of nature — the endowment is denominated in the network's token, miners are not obliged to keep everything, access runs through gateways. The insurance is plain: download your JSON and keep a copy.
If you are going to issue one anyway
An active tier is needed: Spark at $15 gives one Digital Passport, Family Archive at $100 up to ten per account, Digital DNA at $1000 up to a hundred. Until issue is pressed the draft can be edited without limit — an alias of 3 to 32 lower-case characters, a name up to 40, a description up to 280, a manifesto up to 500, links up to 64 and 120 characters, a photograph up to 95 KB. Before issuing, the fields are read aloud; that is the single minute in which anything can still be changed. Afterwards the button goes dark for good: no second passport will appear on the same account, and the system returns the previous address.
The price of having no off switch is exactly symmetrical. Nobody will erase your record — and neither will you. Nobody will rewrite your manifesto — and neither will you. Everything listed above as a limitation is the reverse side of the single useful property, and it is worth agreeing to with open eyes.
Original source
The full article is a 55-minute read: six chapters, including the anatomy of self-sovereign identity with its three verification roles, five practical uses of the document each with an honest boundary, a comparison with a notarial record and RFC 3161 timestamps, eighteen questions and answers, and two live links that open without passing through our sites.
Related analyses
- A Name Against a Permission: did:code, dDOM and the Cost of Leaving DomainsProject chronicle
- A Wallet With No Passport: The Ceiling on AI Financial AutonomyEconomics and the token
- A Manifesto That Turns Into a Budget: Reading Version 2.4Protocols and technology