Where's My Network State Passport? | Grace Rachmany (Berlin Ethereum Day, June 2026)
Berlin Ethereum Meetup·Wed, Sep 9, 2026, 12:00 AM
Despite all the talk of sovereignty, DAOs as a new form of governance, and Network States, the Web3 communities have not solved the problems of identity. In a world where our governments are creating strong surveillance-enabling identity systems, we are still struggling with cross-chain identity, clunky reputation systems, and fragmented systems. Even worse, many of those who declare their commitment to freedom, sovereignty, and privacy are using KYC/AML systems that plug people into the same surveillance systems. Grace Rachmany, director of the Decentralized Identity Foundation, walked through the state of digital identity in the Web3 and Network State world today and asked what it would take to create identity systems that would serve our communities? The Berlin Ethereum Day was a one-day event held on June 15, 2026, during the Berlin Blockchain Week, bringing together speakers from the Ethereum Foundation and the broader FOSS, privacy, and security ecosystems to explore the future of Ethereum and self-sovereign technologies - from technical direction and core values to the challenges and opportunities ahead. Future Meetups and Events: https://www.meetup.com/berlin-ethereum-meetup/ More information on the speakers and the agenda: https://berlinethereumday.com/
Transcript
I am the director of the decentralized identity foundation and I can give a really short answer to the question of why we haven't solved it in the Ethereum community and it's basically because the Ethereum and the crypto community doesn't really want to look at past work that's been done over 20 years. But there's some other problems too. First of all, why do you need uh some sort of identity system? Right? Right now we have some of us have some sort of onchain identity and within our communities we all know each other.
So within our communities we can set our own membership criteria. We can enforce a code of conduct and so all of the internal things that you want to take care of. Make sure that our members get services within Ethereum. You can do that. No problem.
The problem comes when you're partner organizations or people in other ecosystems. So if you wanted to create a movement, whether that could be an ecological movement or it could be a privacy movement, whatever it is, how do you know who the members are of your partner organizations, even pop-up cities, it's a really big problem. When I applied for Futura, which I didn't end up staying here, but one of the questions on the application was, "Have you been to a pop-up city before?" And so I wrote my answer, but who knows? I could write anything.
I mean, if I'm I'm the kind of person who would be a bad actor at a pop-up city, why would I tell the truth? I could just write in that I had been to another pop-up city. And are they going to call every other pop-up? I mean, because that's the other problem, right? They could call the other pop-up city person, but all of that ends up being a huge weight on the person who organizes a conference.
And it's like, was Grace really at your popup? Did she behave properly? Whatever. Does it really mean anything? So even just a simple thing like knowing we've got a community of pop-up cities for a longer term real ecosystem, we can't interoperate without some kind of identity and we certainly can't resolve conflicts.
One of the biggest problems that I found when I interviewed there's like networks of networks. One of the first networks of networks I interviewed was regens unite. I said, "What do you mean unite? Like what does that even mean? Is it just conferences that we're going to go to or do you really know who the regens are?
And the biggest problem that they had and every network has is there's some people who you'd really rather not invite to a party or a conference or you can't trust in some other way. And it might be something simple like they just talk too much. Maybe I talk too much, but you have no way of signaling to the other entity in your group that this person was kicked out because of whatever reason. And then that person, that bad actor might go from pop-up city to popup city or from ecological group to ecological group or from rug to rug and just keep rugging people. And so this is where identity becomes a real big problem.
But the amount of investment you would have to make in identity would be very high compared to the problem. And that's really the main reason. So you can see there's a barrier to collaboration. And in order to have a real ecosystem, you're going to need farms, you're going to need data centers, maybe you want a network state, maybe a hacker space. If you had any of these types of things and you wanted to connect them one to another, you really do need some sort of interoperability protocol.
And what we're doing today is KYC, which means that our identity systems are connected to the default surveillance systems that we all say we don't want to be part of. We're using KYC. We're using governmentissued identities. And now you can get like a ZKP based on your government identity. So I can have zero knowledge proof, but I have to have a governmentissued identity that somehow I upload to the blockchain.
And we're still dependent on the default system. We won't have independence as privacyoriented communities. We won't have independence as individuals. If we're using the KYC or any of the pieces of the identity system, if we need to onboard through banks, we don't have free cryp like crypto that is untraceable. It's the same idea with identity.
So this is the real reason it hasn't happened yet. As a community, if you want to implement an identity solution, there's a cost. It's a time cost. It's an it's a membership. It's like a it's a time cost and it's a a money cost.
So, if I want to have my members, let's say I have a closed group and we all know each other. In order to issue some sort of digital identity or even a physical membership card, somebody's got to be in charge of that. We have to have some kind of multi-IG. We don't want one person to be able to kick somebody out because they're angry at them. So, it needs to be kind of a multi-IG by default.
And almost all of the identity systems today are are you know somebody has god mode and it's like okay we'll just tell Joe that so and so is a member and then Joe put you in or out but if Joe gets angry at somebody you know they could just take you out and sometimes you have multiple god mode like multiple administrators who could all throw each other out like that's no good. So really developing this kind of multi-IG type of community-based orientation system for identification that costs money and it's only worth something if multiple organizations use it. And that's why Google does identity because the profits from identity come at that top layer. If you're Google and you have everybody's data, you have a business case. But if I'm a hacker space or I'm a popup city or I'm a network state, the only thing I get from it is cost.
And it's not until there's a lot of communities using it together that there's a return on investment. And that return on investment might not come to me like as the network state. Maybe the network school puts it out and prosper puts it out and a bunch of hacker spaces, but maybe the actual long-term benefit comes to the individuals and not as a return on investment in monetary terms to me or maybe it comes to the whatever it may the ecological community. So the the initial cost comes to these individual communities but the benefit is only to the network as a whole and to the individuals and so it never gets developed. But what happens is that we're vulnerable because we don't know who to trust and the rugs, thugs, mugs, and all those people are going around without any way of having a trust community.
So, this is the real main reason why this has not happened. Hope that makes sense. People are following that. Who knows? All right, you can ask questions.
Maybe I'll get to my end. I actually have a timer here, so I might actually finish. So there are criteria for privacy preserving identity. This is 10 key pillars that are just summarized, but the American Civil Liberties Union has put out a list of 12. Um Christopher Allen who wrote the first self-s sovereign identity paper maybe 20 odd years ago.
He's just put out an update today. And there are also criteria that are set in place it by Utah's state government in the United States. You may be aware there's something called real ID which is not privacy preserving self-s sovereign identity. And the residents of Utah don't really believe there, as some of you may know, there's like a large Mormon population there. And somebody said, "Oh yeah, that's the capital of tinfoil hat.
Paranoid people." Although every conspiracy theory so far that we've seen just got exposed in the Epstein file. So I don't know about the maybe the tinfoil hats are are right but they don't like this real ID thing and so their parliament has passed or parliament or state government state congress has passed two legislations that outline criteria for identity and they're starting to create self- sovereign identities over there. And what they're calling it is state endorsed identity. And so if you're a Mormon, you don't think that your government gives you identity.
They think that God gives you identity. They might be right. It might be that you just when you get born, you get an identity. It's not something someone gives to you. Maybe your parents give it to you sort of.
So the idea is that different institutions will be able to identity and the state will just endorse, yeah, this is valid in whatever way. maybe you come in person or whatever so that the state endorses it but the state doesn't issue it and this is a much more privacy preserving way of doing it and these are some of the pillars for that. All of you can guess what you want like you don't want your identity when you go somewhere to buy alcohol and you show your driver's license. You don't want that guy to know your age and your country and you don't want the the issuer of that digital identity to know you went there because it's certainly feasible today in many of the government implementations to know that somebody went into a bar and then to know that they're driving home and you don't want that type of surveillance. It's technically possible in some of the implementations today.
Um, so not phoning home, not informing the police, uh, being able to take it to hold it in your own wallet and to take it to another wallet if you don't trust that wallet provider. All of those things are obvious that we want them. I want to hold my credentials. If I want to show somebody I'm over 18, I just want to show them over 18. I don't need to show them my exact age.
I don't need to show them my nationality. So there should be some sort of what you guys would call ZKP, zero knowledge proof. So it separates your identity which is hey my name is Grace. It's not by the way not legally and the credentials that you hold and only expose the credentials that you want to expose. And so these are the principles you want.
Your ENS is not doing that for you. Your crypto identities aren't doing that for you. Having NFTTS or POPS on the blockchain that are kind of credentials exposes you. So if I go to an Ethereum event and I tap my I love my POPs and I tap and I get a POP, somebody can know immediately at that moment that I'm not in my house. It's a liability.
And so you don't want those kinds of liabilities. And that's why blockchainbased identity like you don't want an immutable record about whether you went to the lesbian cafe or whatever else or you belong to that group. Not that there's anything wrong with that, but you don't want that to be a public record. So you have to be very careful about credentials on the blockchain. Blockchain can be used as an anchor for these things, but you don't want your private data on your blockchain.
I think we all know that by now and we're trying to cover it up, but you can't cover it up after the fact, right? It's privacy at the beginning. So, there's a bunch of different architectures. I won't go through them because it's a short talk, but these are the identity architectures that have been classically used. On the left, on the left is sort of the centralized architecture.
Every company uses this right now. It's like your company issues you uh identity and then they give you your Microsoft uh software stuff and then they give you whatever all the permissions within the company. That makes a lot of sense if you're a company, right? I kind of do own your data from a company, but it doesn't make sense for us. Um there's the OOTH model which is on the right.
That's sign in with Google, sign in with Facebook. That's what's being implemented now in Europe with the UD wallets. basically a centralized architecture where it looks a little more decentralized because when you log in with Google it has to ask for permission the app asks for permission and then Google grants the permission and okay Google maybe doesn't have all your application data but it knows every time you logged in and that's the kind of architecture it's called ooth architecture that's being implemented with European identity wallets today so there's always a centralized thing it also assumes connectivity all the because you can't log in with Google if you're not connected to the internet. And so in some developing countries or in places which may be developing in the future, not mentioning any countries, but assuming you're always going to be online is a problem. And I don't know about you, but several times a day my phone asks, "Is this really you?"
So these architectures also are breaking down a bit. Um the blockchain also like I said on on the one hand it can give you a more decentralized kind of thing but the blockchain is still the centralized thing and as we know your Ethereum wallet isn't going to go with your whatever it is Salana wallet or different EVMs even you're going to have to have this centralized architecture where all the identity data is held and that's not where you the the data in the blockchain isn't held by you. it's held on the blockchain. I want to hold it in my wallet just like my physical wallet. I don't want to hold it in the blockchain and just have a public private key.
So these are centralized architectures. We work on a decentralized architecture where the subject in the middle holds it on their wallet. So I hold my digital identifier. When you sign in with Google, what it sends is basically a digital identifier. this is Grace or this is you, whatever they're sending, but you'd like to send that from your wallet.
A wallet would ideally allow you to log in yourself and send your own identifiers. And you might have different identifiers for different contexts. And that should come from you, not from a centralized server. And then the same with your credentials. If someone has given you a credential, so for example, when you graduate from university, they give you a credential, you hold that and you can show it in the physical world, this is my credential and you don't want them to call back to some server.
And of course, the university has it, but there shouldn't be one big server of all your, oh, it's got my university credentials and my driver's license and my health care credentials. And you don't want all those in one big server. You want them in your pocket so you can call them up. or at the very least you want the keys to them in your pocket so you can open the key but they're not held by one central organization and then what the distributed ledger is used for now is that when I present that credential so if I present my over 18 credential or my qualification credential they can go to a distributed ledger which could be a blockchain or any other type of anchor and that gives them the ability to know how to read that credential and it provides as an anchor. So the credential is with me and the private key is with me.
But the ability to open it and to know how to read it, it's not how to open it. I can give permission to open it, but knowing how to read it has to sit in de central repository. So that it and some of these decentralized identifiers are done through web. So there's a web address that you go to and it tells you how to open the key. That could be done by blockchain or other types of registries.
So that's called that's a registry service and that's where blockchain is really important here. Um and we're prototyping something like this. It's on a non-blockchain protocol. But if you want to pro prototype this or try and use some decentralized identifiers, this is one of the projects. It's not our project, but people who are using decentralized identifiers and they're looking for communities and groups who want to actually use this for their communities.
And I'll just give you a little bit of an overview of how they're seeing this. So the way that they're seeing this is this is how we see it. So in diff we have members. So I as the executive director have a list of who's signed a contract and is a member. You have to sign a contract that everything you do is open source.
That's the contract. And each of our working groups has is self-referential. So I don't decide who's in the working group. The working group members decide who's a member of the group. And so the infrastructure that I just showed you is designed so that a community can say these are our members.
So that the identity doesn't come from a government. It doesn't come from me as the executive director. It comes from internal to that community. And so these are interoperable identities that communities can implement and they can create the rules. They can say this is our council.
All five of these people have to approve a membership or three of them. However you want to identify who are the people to give the credentials you can do that. So this is much more community-based. It's a trust graphbased thing but you can decide the rules for your community. The other thing that we and like I said this is based on a web- based protocol called did webvh right now at diff there's something called did e ether and not surprising it's based on the ethereum network.
So this is now undergoing a review process in our organization to be a recommended method. In order to be a recommended method they're looking for who's actually implemented it. How many deployments is there? And they're also looking for some information like feedback on the specifications to make sure this really works. So if you're interested in really having Ethereum as part of the decentralized world, please come and contribute.
At this point, it's not about contributing code, but is about sort of running it through making sure that this is a solid standard or using it for your protocol. Why not use it if you're trying to do identity on Ethereum? And the only qualification is that you need to sign an IPR agreement that all of your contributions are open source under the Apache 2 license. Most of you will be cool with that. So far, the Ethereum Foundation has not signed on that.
So, if you know somebody in Ethereum Foundation who would like to sign on that, you texted her. Please have the Ethereum Foundation please sign so that you, those of you who do work for the Ethereum Foundation can also be contributors. We're all on the same team here. We really want decentralized identity. We want it to be interoperable.
We want it to be on Ethereum and not on web DNS. Not bad, but okay. Thank you.
Automatic transcript — names and jargon may be misspelled.