Everyone discussing Dusk starts with privacy. I want to start one layer earlier, because privacy is not where compliance actually begins.
It begins with identity.
Think about what a regulated venue needs before a single trade happens. Is this person eligible to hold this instrument. Are they in a permitted jurisdiction. Have they passed KYC. Professional or retail. None of that is a transaction question. It is an admission question, answered before anything touches the ledger.
Most chains have no answer here at all, so the answer gets outsourced. A whitelist contract. An offchain KYC provider. An admin key deciding who is allowed in.
And that whitelist is the weak point. It is a honeypot, a single point of failure, and a very ordinary intermediary wearing a technical costume.
Citadel is Dusk's attempt at the other approach. An authorised issuer grants you a credential. Later you prove to a contract that you hold a valid credential meeting the required conditions, without handing over the underlying identity and without the verifier learning who you are. Eligibility becomes something you prove rather than something someone looks up.
If that works properly, the whitelist stops existing as a list at all.
Here is the part I keep turning over though. The issuer still has to be someone. Someone licensed, someone trusted, someone who can also decide not to issue. The cryptography removes the database. It does not remove the gatekeeper. It relocates them.
Maybe that is simply correct. Regulated markets are supposed to have gatekeepers, that is what a licence is. But then the honest description is not permissionless finance with privacy. It is permissioned finance with much better privacy. Smaller claim, more useful one.
@Dusk_Foundation am I reading this right, or does the credential model shift the gatekeeper's power in a way I am missing?
Curious what people here think identity should actually look like onchain. I have not seen a version I am fully convinced by.
@Dusk_Foundation $DUSK #dusk #RWA
It begins with identity.
Think about what a regulated venue needs before a single trade happens. Is this person eligible to hold this instrument. Are they in a permitted jurisdiction. Have they passed KYC. Professional or retail. None of that is a transaction question. It is an admission question, answered before anything touches the ledger.
Most chains have no answer here at all, so the answer gets outsourced. A whitelist contract. An offchain KYC provider. An admin key deciding who is allowed in.
And that whitelist is the weak point. It is a honeypot, a single point of failure, and a very ordinary intermediary wearing a technical costume.
Citadel is Dusk's attempt at the other approach. An authorised issuer grants you a credential. Later you prove to a contract that you hold a valid credential meeting the required conditions, without handing over the underlying identity and without the verifier learning who you are. Eligibility becomes something you prove rather than something someone looks up.
If that works properly, the whitelist stops existing as a list at all.
Here is the part I keep turning over though. The issuer still has to be someone. Someone licensed, someone trusted, someone who can also decide not to issue. The cryptography removes the database. It does not remove the gatekeeper. It relocates them.
Maybe that is simply correct. Regulated markets are supposed to have gatekeepers, that is what a licence is. But then the honest description is not permissionless finance with privacy. It is permissioned finance with much better privacy. Smaller claim, more useful one.
@Dusk_Foundation am I reading this right, or does the credential model shift the gatekeeper's power in a way I am missing?
Curious what people here think identity should actually look like onchain. I have not seen a version I am fully convinced by.
@Dusk_Foundation $DUSK #dusk #RWA