After actually using over a dozen DeFi apps that require KYC, I went back through old records and found a painful fact: over the past two years, I’ve uploaded my ID at least 8 times and done face recognition 6 times. The same identity information is scattered across different platforms’ servers. Who stores it, how long it’s kept, and whether it could be leaked in a database breach—all of that is completely out of the user’s control. That’s what makes "secondary KYC" so infuriating.
After digging into the "use case B" of @NewtonProtocol Newton VC, the key issue is actually the boundary of credential reusability. After a user completes KYC on platform A and generates a Newton VC, platform B theoretically only needs to verify the conclusion that "this credential is valid" and doesn’t need to touch the user’s original identity data. But the biggest practical problem is this: different dApps do not have a unified compliance standard for what counts as "valid KYC." Platform A may use a simplified review process, while platform B may require stricter institution-level compliance. Can this credential really be reused directly? Who defines the mutual recognition standard? The white paper gives no answer.
Looking deeper, the risk of credentials being stolen or forged has not disappeared either; it has only taken on a new form. Before, it was identity card photos being stolen; now, it’s credential private keys or session keys being stolen. Once a credential is misused, the victim may find it even harder to prove innocence than in a traditional KYC data leak, because the phrase "my credential shows that I have passed verification" itself becomes the attacker’s best shield. #Newt
My personal view is this: the direction is absolutely right. Privacy-domain sharing will eventually become a standard across the industry, but at this stage I would not hand all sensitive operations over to a single credential. For important transactions, I would still keep the habit of manual secondary confirmation. $NEWT
It’s not that I’m pessimistic about this mechanism. Quite the opposite—because I believe in it, I think we need to pay even closer attention to the implementation details. Experienced users understand this: when it comes to convenience and security, you always have to think carefully about where the cost really lies.
After digging into the "use case B" of @NewtonProtocol Newton VC, the key issue is actually the boundary of credential reusability. After a user completes KYC on platform A and generates a Newton VC, platform B theoretically only needs to verify the conclusion that "this credential is valid" and doesn’t need to touch the user’s original identity data. But the biggest practical problem is this: different dApps do not have a unified compliance standard for what counts as "valid KYC." Platform A may use a simplified review process, while platform B may require stricter institution-level compliance. Can this credential really be reused directly? Who defines the mutual recognition standard? The white paper gives no answer.
Looking deeper, the risk of credentials being stolen or forged has not disappeared either; it has only taken on a new form. Before, it was identity card photos being stolen; now, it’s credential private keys or session keys being stolen. Once a credential is misused, the victim may find it even harder to prove innocence than in a traditional KYC data leak, because the phrase "my credential shows that I have passed verification" itself becomes the attacker’s best shield. #Newt
My personal view is this: the direction is absolutely right. Privacy-domain sharing will eventually become a standard across the industry, but at this stage I would not hand all sensitive operations over to a single credential. For important transactions, I would still keep the habit of manual secondary confirmation. $NEWT
It’s not that I’m pessimistic about this mechanism. Quite the opposite—because I believe in it, I think we need to pay even closer attention to the implementation details. Experienced users understand this: when it comes to convenience and security, you always have to think carefully about where the cost really lies.