Jonathan Chew · · 6 min read

Understanding the latest evolution in digital identity protection

In partnership withAffinidi

“A login was detected on a new device. If this action was not performed by you, please contact us.”

Receiving this message when you have not, in fact, made a login attempt can be one of the most unnerving things in the world. Somewhere out there, someone has gotten hold of your personal details and is masquerading as you.

Photo credit: Shutterstock

Unfortunately, simple passwords just don’t cut it these days, and we’re seeing more sophisticated methods to protect peoples’ digital identities. Two-factor authentication and biometric logins are just some examples.

“There’s so much information being exchanged that passwords alone have become kind of outdated to solve for our data protection needs,” says Junius Ho, chief product officer of data empowerment startup Affinidi.

The evolution of digital identity protection

The advent of Web2 led to a huge wave of new online services, and people started to need more than just one or two passwords.

This led to the rise of single sign-on and federated identity solutions, which allowed people to use one set of login credentials for multiple applications or networks.

However, these solutions were mainly limited to companies and enterprises at the time, says Ho. The average internet user needed something similar, but it had to apply to an even wider range of online services.

Enter social logins.

With social logins, users could sign up for new online services with their social media accounts, a capability that’s “carried us over the last decade or so,” says Ho.

Junius Ho, chief product officer of Affinidi / Photo credit: Affinidi

“But in doing so, we’ve given up some things. While we got convenience, the consequence is that now, we’re able to be tracked over everything that we used social logins to access,” he adds.

Additionally, social logins didn’t really change the fact that many people still relied on an inordinate amount of passwords – a recent study showed that the average person has a whopping 100 of them.

We’ve even started seeing another layer of solutions – such as password managers – to help people remember all their login details.

“When you need a solution for a solution – like now, when too many passwords creates a problem – then you need a more fundamental shift,” says the chief product officer.

Taking passwords out of the equation

This is where the concept of passwordless authentication comes in.

As the name suggests, passwordless authentication means getting rid of the need to remember scores of login credentials and relying on uniquely individual identifiers instead. Some tech giants are already pushing the concept. For example, Google and Amazon are both exploring passkeys that rely on biometric authentication.

However, while these passwordless options are great, Ho points out that much of the power in information sharing still lies with companies. Ultimately, that means that shifting to passwordless authentication only solves one piece of the puzzle in digital identity management.

Currently, if a business wants a certain piece of information from you – say, your birthday for a birthday month promotion – the way that it obtains that data is by accessing your full birthday based on your login method. For example, if you used a social login, the business would see your entire birthday as stored in your social media profile.

“Does that business really need to know my birth year too? It might only need my birthdate or birth month, but if I used a social login, I can’t be that specific,” Ho points out.

Solving this will take more than a different approach to passwords – rather, the entire system is in need of an overhaul.

U-turn

What Ho suggests is to “flip the script,” combining the latest passwordless authentication capabilities with solutions that give consumers more specific control over the details they want to reveal.

This concept is known as holistic identity management.

It’s central to changing how digital identity management works because this time, companies don’t actually need to request for and store customers’ personal information themselves. In fact, it’s the consumers that get to make the decision to share that data, all while keeping their own personal details under lock and key.

Photo credit: Shutterstock

“This innovation empowers people to take complete control of their digital identities,” Ho says.

One of the ways to execute this concept is by enabling consumers to store personal information on their own edge devices. This is something that Affinidi offers through the Affinidi Vault, which allows users to store and control their data in a way that aligns with their preferences and values.

Let’s say you’re trying to buy something on an ecommerce site. The business might want to know details such as your gender and favorite clothing brands. If these details are already stored in your Affinidi Vault, the ecommerce store can request to pull those specific pieces of information from the Vault. And with the firm’s Affinidi Login solution, a passwordless authentication product that verifies the user’s identity without the need for traditional passwords, the process becomes more seamless and secure.

With one click, you would be able to provide only relevant details to the service provider, allowing the business to give you a better, personalized experience without needing an entire sign up process. To make things simpler, the firm also offers a private AI personal assistant, called Affinidi Concierge, which further optimizes and manages the use of your stored data, allowing for greater privacy and security.

The best part is that you won’t need to disclose personally identifiable information to get this experience. Ultimately, companies only need to know what you like or don’t like to customize things, but they don’t actually need to know who you are to do that. As long as you remain logged in with that third party service and it’s linked up with their platforms, then you’re all set.

Everything’s built on trust

Of course, all this is predicated on the assumption that the consumer is providing accurate information and not just inputting junk information. Incorporating OpenID for Verifiable Presentations (OID4VP) would solve that potential issue.

OID4VP is an open-sourced standard that allows for the sharing of information in a secure and authenticated way.

There’s so much information being exchanged that passwords alone have become kind of outdated to solve for our data protection needs

Take for example a Singaporean consumer that wants to add 1996 as their birth year to their Affinidi Vault. When they want to do so, applying the OID4VP standard means that they can verify that the information is accurate by authenticating it through an official body, like Singpass, a digital identity service run by the Singapore government.

“It’s also better because this specific standard allows users to selectively share only what they want,” he adds. “At the same time, companies can benefit because having OID4VP lets them know the data comes from a trusted source.”

Bringing everything together

As this new data sharing concept gets adopted more widely, Ho hopes that it’ll lead to a better relationship between users and businesses.

“The next big step is to offer opportunities to share more than just the basics of who you are, like your name and email address,” he says. “It’s all about how we can now build a more trusting relationship, and where you can share more information about yourself, perhaps even in exchange for getting better offers from the service you’re signing up for.”

Ultimately, this should lead to greater convenience for everyone involved without compromising privacy.

“Passwordless authentication won’t just affect signing in,” he says. “It’ll also merge signing up, registration, and everything else at that stage into a single step. If you can pull everything into a single step, it becomes super powerful.”


Affinidi is a technology company dedicated to changing data ownership for good. It’s guided by a “privacy by design” philosophy, meaning that customer data isn’t simply a priority – it has to be something that’s inherently built into its tech stack. To find out more, visit its website here.

VISIT SITE


This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

How would you feel if you could no longer use Tech in Asia?

Editing by Stefanie Yeo and Jaclyn Tiu

(And yes, we’re serious about ethics and transparency. More information here.)

TIA Writer

Jonathan Chew

Has a strange liking for grabbing tiny plastic things on wooden walls