Ideas

ID.me.

Laptop showing an ID.me concept login with a rotating-hash security graphic, beside an Ideas Into Real Solutions mug've been carrying since 2022, with the registration panel showing what is hashed and what is not

Everyone signs up for everything now. Every app, every newsletter, every shop wants an account. And every one of those accounts sits in a database somewhere with your name, your email, your phone, sometimes a lot more.

Every database leaks eventually. When it does, all of that walks out the door in one go, and whoever picks it up knows exactly who to target.

I couldn't stop thinking about that.

The idea came from crypto. I'm not a crypto guru. I was just curious how the thing works, and one part of it stuck with me: you can see a wallet and what's in it, but you have no idea who it belongs to. I wanted a database like that. If someone breaks in, they get a pile of numbers and hashes that don't point at anyone.

So that's what ID.me is. My first shot at it.

How it works

You log in with three secrets: a username, a number that's yours, and a password. Get any one wrong and it says the same thing, so nobody learns which one they got right.

Your number picks one of 1,024 ways to mix your password before it's stored. Which one it picked isn't written down anywhere. And every time you log in, the stored hash changes. What leaked yesterday is already wrong today.

Nothing is stored in plain text. Not your email, not your name. When you register, a panel on the screen shows you exactly what goes into the database and what never does.

Try it with nonsense

You don't need to give it anything real. Fake name, made-up email, a password you'll forget in a minute. Even the recovery story, the questions from your life, you can fill with rubbish. The point isn't to sign you up. The point is that after you do it, the panel shows you what actually landed in the database. Look at it. That's the whole proof. If there's nothing in there worth stealing, the idea works. If you can find something, tell me.

The part that sounds like a problem, and isn't

Because I don't keep your email, I can't email you. Ever. I can't contact you at all, unless you log in, and then whatever I need to tell you is waiting inside the app.

I did that on purpose. I skip most of the emails I get. Half of them go to junk without me reading them. If I have something to say to the people using a thing I built, it should be there when they open it, not buried under twenty offers.

What I'm not claiming

I'm not a security researcher. This isn't production-ready. Somebody with the server itself in their hands is a problem I haven't solved. If a database leaks, what comes out is a lot less useful than usual. Not nothing. Less. I believe it's a better shape than what most of us are handing our details to today, and I'd like to be told where I'm wrong.

Where it's at

I built the first version a couple of months ago and then other projects took me. It needs attention. Recovery works with a seed phrase and questions from your own life, borrowed from crypto, and I think I've got better ideas for that part.

When it's the way I want it, I'll probably use it under the things I build for this brand. Maybe the timesheet app. Maybe an app for ZeroWic itself, so the people who want to follow along can do that inside an app instead of through an inbox. Maybe. No dates.

It's live. Not finished, live. Have a look, try it, break it. And if you have an idea, or you found the hole, say hello. That's what the page is for.

Try ID.me