What if the biggest weakness in digital identity is not proving who you are, but revealing too much while doing it?
I ran into DUSK’s Citadel identity design while researching infrastructure for regulated markets, and that question stayed with me. Traditional verification often works by collecting more information than the actual decision requires. If a service only needs to know that I meet an age, jurisdiction, or eligibility condition, why should it automatically receive the rest of my personal details?
Citadel takes a different approach. A user can hold a signed credential and later generate a zero-knowledge proof showing that the credential is valid without putting the underlying personal attributes on-chain. The service still decides whether that proof satisfies its own policy.
That separation is what I find interesting.
The blockchain does not need to become a giant database of identities to make identity useful. It can instead become a place where specific claims are verified while the underlying information remains controlled by the person who owns it.
While exploring this, I started thinking about how often “compliance” is treated as an excuse for collecting everything. In many systems, proving eligibility and surrendering personal data have become almost inseparable.
DUSK makes me question whether that relationship is necessary.
There is also a subtle shift in responsibility here: the protocol can verify that a credential or proof is valid, while the service provider still decides what it accepts. That keeps policy separate from cryptographic verification.
Maybe better digital identity is not about creating a more complete profile of everyone, but about making smaller, precise claims easier to verify.
That distinction feels worth watching as financial infrastructure becomes increasingly digital.
#dusk $DUSK @Dusk
I ran into DUSK’s Citadel identity design while researching infrastructure for regulated markets, and that question stayed with me. Traditional verification often works by collecting more information than the actual decision requires. If a service only needs to know that I meet an age, jurisdiction, or eligibility condition, why should it automatically receive the rest of my personal details?
Citadel takes a different approach. A user can hold a signed credential and later generate a zero-knowledge proof showing that the credential is valid without putting the underlying personal attributes on-chain. The service still decides whether that proof satisfies its own policy.
That separation is what I find interesting.
The blockchain does not need to become a giant database of identities to make identity useful. It can instead become a place where specific claims are verified while the underlying information remains controlled by the person who owns it.
While exploring this, I started thinking about how often “compliance” is treated as an excuse for collecting everything. In many systems, proving eligibility and surrendering personal data have become almost inseparable.
DUSK makes me question whether that relationship is necessary.
There is also a subtle shift in responsibility here: the protocol can verify that a credential or proof is valid, while the service provider still decides what it accepts. That keeps policy separate from cryptographic verification.
Maybe better digital identity is not about creating a more complete profile of everyone, but about making smaller, precise claims easier to verify.
That distinction feels worth watching as financial infrastructure becomes increasingly digital.
#dusk $DUSK @Dusk

