Thank you, Jason. This is exactly the thesis we've been building Didit around since day one.
Trust is one of the oldest technologies humanity has. Long before money or cities, it was what allowed people to cooperate. And almost every major step forward in civilization was, at its core, an innovation in trust: written contracts let us rely on promises, signatures let us verify where a document came from, banks let us trust that our savings would still be there tomorrow, and passports let a border officer trust that a stranger is who they claim to be. Societies scaled the moment strangers could trust each other.
The internet connected billions of strangers faster than any technology in history, but it was built to move information, not to establish who is on the other side. So every company rebuilt its own version of trust: its own onboarding checks, its own document uploads, its own fraud team. People verify themselves again and again, businesses pay repeatedly to learn the same things, and fake accounts, bots and fraud remain a cost built into almost every online service.
Payments went through the same phase. Every merchant had to solve it on their own until a payments layer emerged, and that single piece of infrastructure unlocked e-commerce, subscriptions, marketplaces and much of the modern internet economy. Trust has never had that moment.
AI makes it urgent. Faces, voices, documents and entire identities can now be generated at almost no cost. When faking becomes free, proof becomes the most valuable signal online: is this a real person, are they who they say they are, and is this AI agent actually authorized to act on someone's behalf? As more activity online is carried out by agents, every one of those interactions will need an answer.
Payments answer whether value can move. Trust answers whether it should. That's why we believe trust will become even more important than payments, and a layer every application will need, not just a feature some of them add.
How this layer gets built matters as much as whether it gets built. At Didit we hold a few principles:
- Accessible. Trust infrastructure can't be a privilege of large enterprises. A two-person startup should have access to the same protection as a global institution, and every individual, anywhere in the world, should be able to use it.
- Private. People should be able to prove what matters without giving away more than necessary. Personal data belongs to the person.
- Portable. Verification shouldn't start from zero with every new service. Trust should move with the individual.
- Simple. A few lines of code for developers and a few seconds for users.
Civilization scaled when we learned to trust strangers. The internet will reach its full potential when trust is as native to it as sending a message. That's the future we're building at Didit, and we're accelerating.
Gotta give it to
@nikitabier - he knows the perfect way to illustrate the future. What would happen if bots pursued unlimited refund requests?
Stunts like this are Rorschach Test.
For those that are scared about the future, they will see this and see havoc caused by AI.
They will see Nikita‘s post as reckless because it exposes a vulnerability, takes advantage of a system unprepared for a new technology and then foolishly shares it on the Internet, where anyone else can copy it.
Of course those who built defense systems before see this very differently.
This is a hypothetical scenario that allows people to understand what defense systems they will need as challenges like this proliferate.
On November 2 1988, the "Internet" was brought down by the Robert Morris worm, an accidental website counter built by a single computer scientist who was curious how many websites existed on the Internet but forgot to tell the bot not to count websites it had already checked. It brought down a meaningful portion of the Internet as its bot multiplied uncontrollably.
(Note - I'm using the words website and internet, our later words for it - this was actually a unix worm on the Arpanet in the primordial soup of what would become the internet)
Early YC Founders know the story because Robert Morris is one of the original Founders of Y Combinator.
The solution wasn’t to convince everyone never to make a website counter or prevent the technology of website counters from existing or to make it so that the government had to review all website counters before website counters could be provided to the public.
No, the solution was companies like Cloudflare, which stop both innocent and malicious distributed denial of service attacks by sitting in front of every website and for a relatively tiny fee, monitoring the Internet activity in order to protect local websites.
Today Cloudflare and an entire security industry stop thousands of attacks per hour. For the rest of society, we don't notice except every once in awhile when one briefly gets through. It's hard work by talented people, but it's not a societal risk.
The Robert Morris worm was an innocent example of future havoc that could be wrecked on the Internet economy.
The solution was an innovative company solving the problem. DDOS attacks have not been a significant problem for the last 30 years.
What’s the solution to the Nikita bot swarm refund request example?
It’s companies like
@didit.
We invested in
@albertorosasg and
@_arosasg's human verification company to solve this exact problem. They’re the best. fastest, cheapest way for any company to verify they’re talking to a human and not an agent.
They will need to be as big as CloudFlare because 100% of all businesses will need it.
Might be a good time to speed up guys.