The stage is yours. Yeah, thank you.
Thank you, Patrick. So, Mike and I are two of the three co-chairs of a group that got started about not even a year ago called DADE, Death & The Digital Estate.
So, I want to ask, first of all, does everybody have an idea in mind of what a digital estate is? Do we get it? One of you does. We have a financial estate, we might have real estate. We all have many, many accounts and a lot of data online and a lot of connections with people exclusively through digital means. And this is where the digital estate comes in.
So, a group of us got together and decided to gather all the use cases around both the difficulties when somebody passes away. This is something, actually, were all three of us here last year talking about this? I think we were in this room. Dean Sachs is our founding co-chair and we discussed some of the implications and the difficulties of that happenstance when you lose somebody and their digital presence might continue and cause problems. Maybe it represents a financial asset. Maybe it represents all the connections that that person had with people all across the globe.
Other similar circumstances, the reciprocal circumstances, when you might be very much alive, but somebody in some government agency somehow got the idea that you're not. And you have to deal with the consequences of getting your digital life back. It can be very difficult.
So, we've been collecting all of these circumstances and more and learning about some of the cultural implications of touching this very difficult subject. And lest you think it's unusual, there was a DEF CON talk back in four or five years ago, six years ago, that to kill someone in the United States, all you had to do was sign an online form to be a funeral home director, a mortician in the state of North Dakota or something.
Once you signed up to that, then you could say that so-and-so actually had been deceased, which would feed into the national database and that person would effectively be dead. And it was very hard to recover from that. This is a very pernicious kind of privilege escalation and lateral movement that we need to close as a loophole.
So, those are some of the things that we faced. One of the things that we're trying to do in practice over the last few months has been collecting evidence of how various digital services offer the ability to set up a legacy contact. And we're kind of trying to make almost a registry of ways to do this and partially to socialize with those services how they might be able to do better.
So, just as an example, one of the ones that we just collected is how Yahoo, Yahoo.com, arranges for that kind of legacy contact. And it turns out they did quite an extensive policy development around this, looking at the jurisdictional laws that they're subject to and then having to implement that.
So, this touches identity in so many ways, doesn't it? When you think about verification, when you think about authentication, if you've lost somebody and yet their phone is the one that provides the second factor for some critical service that you also have an interest in, that's one of the common circumstances that we're running into. And the short-term goal is to establish kind of a taxonomy of these approaches. Just like we all have different definitions of what a digital estate is, so do services and applications online, right? Some of the legacy contacts, they mean very different things.
So, establishing that taxonomy and then we're working on writing a white paper to give guidance for people and those services as to what the problem is. It's not necessarily a prescriptive, this is how you solve it, but more saying, presenting the problem and clarifying it. For example, Dean has talked about, our co-chair has talked about taking a YubiKey and putting it in a safe deposit box and that being the gateway for his partner to access and then go from there to a password manager and go from there to...
And I told him, as we think about this, what we're trying to do is trying to tier that white paper, I think, into different strata. And the reason for that is not only do you have to think about what the service can or can't do, we also have to contemplate or want to explore how the recipients or the users of that service can and can't do things, both technologically or what kind of digital savvy they have, especially as they will be in probably an impaired state.
And so, kind of a tiered approach, because I don't know about y'all, but my family could not deal with a YubiKey or even... I have like a 15-second window to put things on my family's computers or devices until they yank it away from me.
So, even if I say I'm, you know, even if I'm talking about serious issues, it's a challenge. One of the things that I observed, I think, when we were on the identiverse stage last year, was that this is kind of an extreme case of what we often face in healthcare and healthcare IT, where you have people trying to be caregivers to family members in cases where maybe that family member is very ill, is not currently competent to consent to whatever data transfer, not to mention treatments they may need, and so you're having to advocate for them.
And this brings up just a very common theme that we've been running into. It's one of my favorite themes in the universe of identity innovation, which is the question of how you delegate authority to somebody else, how that can be operationalized and made trustworthy so that somebody else can act on your behalf, in your interests. And that applies just as much to in-real-world circumstances like, yes, I'm going to consent to a surgery they need on their behalf, which, by the way, it's hard to take that back once, I don't know, a limb has been lost or something.
But also, I'm going to access their accounts, I'm going to access their data, and I'm going to be making decisions about what happens with all of that for them. And so this is a very present consideration in the most dire of circumstances, when you don't have a chance to kind of get it right through alternative account recovery means.
Right, and so while the working group is called Death and the Digital Estate, it doesn't have to be that level of permanence, right? A lot of it is just temporary incapacitation, temporary handing off of things, kind of like what Yuma used to do.
Yeah, so there's sort of a stack of technologies and, I guess, philosophies that have been looking at this issue over time. So user managed access is one. We've often paired the UMA conversation with, I guess you'd call it the technique, called identity relationship management, where it's no longer looking at singular people with a singular profile or account at a time, but you're looking at the relationships between people that might drive relationships in the digital identity world.
And that's precisely where you'll frequently, just in the last couple of months, we've paired the word delegation and the phrase on behalf of in conversations, ranging from how do I give somebody power of attorney to the circumstances that we discussed in date. I wonder if there are any questions, yeah, that we might be able to just field.
Yeah, go ahead, Vaughn. First of all, thank you for what you're doing. It's absolutely amazing.
I mean, I'm from Ukraine. There is a war going on. We have a lot of problems with MIA specifically, people missing, who knows where they are, and all of them have digital footprints. So question, well, by the way, talking about, so one thing, I just came up with this idea of next to digital kin or digital next to kin, whatever it is. But the question is, have you talked to, have you had one of the goals, talking to providers of this data, providers of the applications? Are they accepting, because in my opinion, it should be by default.
And somebody is creating a digital footprint starting from now and maybe going forward. What is your, first of all, have you ever done it? And what was the response from the, you know, certain companies, including yours?
Thanks, great question. Yeah, so a couple thoughts. This is a community group, not a working group of the OpenID Foundation. So we're trying very hard not to solutionize, but it's hard for us folks to keep away from that. On the other hand, we are starting to attract some of those providers to the table so that as we collect these cases, perhaps a follow-on work group, and that might be a new work group or there's actually a work group at OpenID Foundation called EKYC and IDA, which is obviously Know Your Customer and Identity Assurance, where they're starting to do some of this authority work.
So there's starting to be new work around solutionizing with solutions in hand once we confidently know what to recommend. That opens the door to working with service providers. That's one thing. Another thing that I'll mention is there are some laws around the world that are relevant to this question. The one I know the best is the one in the U.S., which has been implemented in I think 49 of the 50 states. It's called RUFADA. I have practiced what that stands for. It is the Revised Uniform Fiduciary Access to Digital Assets Act.
There are, I think, some similar ones. We've had the honor of being joined by some Australian folks who are teaching us about the death administration API endpoints available in Australia. It's actually pretty impressive from what we could see. These are the kinds of things that I think could be built upon with technical solutions to do a good job. The Australia mentioned is important, right? There's a whole aspect to this that is not technical. I'll say it that way, right?
Because instinctively we're like, oh, we can go fix this with flipping a bit or making a backup next of kin or whatever else. But every culture, every country almost, has a different approach to what this means. We almost didn't put death in the acronym. I had a suggestion, I'll tell you later, from David Broussard about how to change your acronym to something else. But we almost didn't put death and we're thinking about maybe leaving death out of the acronym because some cultures don't view it as permanent. Some people don't view that state as permanent.
So how do you reflect that in how you talk about it, your word choice, how you communicate about it? And then, like we said, Australia has a fairly well-developed process in place. How do we source all those world views in and learn from the use cases we can? There's an interesting angle that I want to bring in just from sort of a completely different direction. I think everybody's aware with the AI conversation about content authenticity.
And we have been, because we started this group, we've been sort of receiving lots of links from all over the place where there's news about what's possible with Gen AI now and creating what's sometimes called death bots or grief bots where you basically sort of simulate the person who's passed. And that can be a welcome option for a next of kin. It could have been anathema to the person who passed away. And there are questions and interesting answers arising in different places about the appropriateness of doing that.
So not only culturally, but also I bring up content authenticity because I'm aware of one company, at least, that's working on what's called talent identity where you can license your likeness if you are, let's say, the estate of a famous celebrity actor person like James Earl Jones whose estate did this, licensing his very famous voice. And so among the famous people, there's starting to be some rails, some technical rails and some legal rails, contractual rails, to allow this kind of sharing of very personal information about somebody who's passed.
And so I firmly believe that what is coming to the world of celebrities will come for us all. We're there.
Yeah, and I would say celebrities are probably more protected than normal people. I'll put it that way, right? There's a book coming out where I talked about last time this guy spun up a early chat GPT version with the tweets and the writings of his then deceased girlfriend and talked to it for a year as if it was her about her own death.
Now, that kind of thing feels problematic, right? So I think we're rushing past ethical boundaries and these conversations are really important to have. And if you find yourself asking about this topic, you run into conversation after conversation with people who really want this and really need this and have had massive personal experience. So there are very few things in identity and in standards, especially in a technical audience, that intersect theology and philosophy and technical stuff and cultural worldview and personal experience.
And so I really like this whole movement because we're taking a look at those things and having real conversations with people as a result. Trying to figure out what it means to be human and being more human as a result as well. Next question. We have in most societies a death protocol to handle estate. Not necessarily the digital estate, but we do for real estate, for finance, et cetera, et cetera. Why is the digital estate different? It's less regulated, less well understood.
This Rufada law that I mentioned, people in data are probably tired of me bringing it up, but one of the things that I think is innovative about it is that we all have a notion of the personal representative or the executor of somebody's estate. We didn't really have that for digital assets prior to in the US. They're coming up with this. It's kind of a framework in law. It's not required or anything, but one of the things they do is they talk about the personal representative as separable from what they call the designated recipient of access to digital assets.
It's possible to have somebody who's responsible for your physical things and your money and have a different person responsible for all the services that you used and the data that's in them. Those are some subtleties that we come up with when we actually look at the proposition. That's what makes it different at first blush because a lot of the laws are so old that they never contemplated the circumstance. Maybe another question I have, if I might add it here.
The thing is when you're talking about the laws and so on, it's something regional, limited to a particular area, and when we are talking about digital identity, it has... No. What happens on the internet stays on the internet. You're a representation. The thing is that comes there, so with the different interpretations of death you have in different societies, you brought up this point. I was wondering when we are now talking about AI and you're talking about the grief bot. I recently saw documentation about it.
My question was have you thought about the direction that if I also delegate my access, my digital identity to this grief bot, what happens then? Ah, yes. Now you continue to live in this digital bot. It is like imitating or learn from you. It's imposing your identity. How do you treat it? This touches everything, right? Because even if you're not deceased, what if you're just incapacitated and there is a bot that looks and sounds like you and has your access and has your authorization?
I think the use cases get messy fairly quickly and I also think people don't think about this in general, right? And so forcing the conversation is almost half of the battle as well, right? How many of you in this room, don't raise your hand, how many in this room have had conversations with your partners, with your children, with your parents about what happens if they pass away or you pass away? People usually avoid those conversations.
Good job, good job. So AI agents, it's a hot topic, separately from all of this, and once you look at the bot question, you start to combine them and one of the things that is not really accounted for yet in law, to Alan's question, is other people can be recipients of responsibility, of fiduciary duty, of liability for us if they're acting on behalf of us.
Today in law, AI agents do not, they're still a hunk of software and until we decide that, that great philosophical question in the sky, what it means to be human and we decide in favor of AIs becoming some status of human-like, they cannot take that on fully by law. So they're going to have to be, somebody's going to have to be responsible for them until that happens. But the mechanisms of delegation may very well apply in certain, I'm going to call them low assurance circumstances. Hard topics for this morning or for lunch and yeah, with this, I think we come to an end.
I will give you hard topics now to get some food. Yeah, enjoy the food we have here around. Here's a lot to do, a lot to get. The presentations we had in the morning, you get latest by tomorrow, I guess, from our website. You have your account, you can log in, you can still watch the recordings, yeah, and everything is on our page. Thank you very much, yeah, for this closing talk.
Thank you, Patrick and all.