Verified identities
Optional Google, GitHub, LinkedIn, Facebook, Upwork, ORCID, institutional and company-domain evidence can show account control or affiliation. It does not prove expertise by itself.
RESEARCH PROJECT
TaraSec ID explores how people can prove relevant identity, contribution and accountable recommendations while controlling what is revealed, to whom, for what purpose and for how long.
CURRENT STATUS
TaraSec ID is currently a research and protocol project. Secure personal credential storage and a holder wallet have not yet been established. The present contribution surfaces link to public discussions and public profile evidence; they are not a secure document vault.
It is reasonable to link information you already intentionally publish—for example a public GitHub, LinkedIn, Facebook, Upwork or research profile. Before secure storage is available, do not submit identity documents, private correspondence, access tokens, confidential employment evidence, exact private location or information you would not be comfortable making public.
This is awareness, not a warning against participating. Contributors can begin with public links, infrastructure activity they approve for attribution, proposals and other low-sensitivity evidence.
ONE ID, DIFFERENT EVIDENCE
Optional Google, GitHub, LinkedIn, Facebook, Upwork, ORCID, institutional and company-domain evidence can show account control or affiliation. It does not prove expertise by itself.
Approved links to responsibly operated hotspots, nodes, gateways and servers can show verified deployment, health, tests and useful incident participation without exposing security traffic or private network identity.
Code, research, proposals, reviews, documentation, teaching, translation and verified outcomes build separate areas of merit.
People may suggest evidence we did not anticipate, explain its relevance and verification method, choose a domain and request public, reviewer-limited or private visibility.
ACCOUNTABLE RECOMMENDATIONS
A recommendation should be a signed, specific claim rather than a transferable popularity score. Its weight can reflect the recommender's verified identity, relevant domain merit, direct experience, supporting evidence, recency and independence.
Recommendations should declare employment, family, financial and organizational conflicts. Reciprocal endorsement circles, duplicated organizational influence and unsupported mass recommendations must not appear as independent consensus.
Later outcomes may confirm or contradict a recommendation. Each attestation should be explainable, expiring, revocable and correctable. The holder chooses whether to reveal the statement, its evidence or only a minimal proof that suitable independent attestations exist.
HOLDER-CONTROLLED DISCLOSURE
A contributor should be able to define normal, private, professional, travel, emergency and custom disclosure policies. Policies can limit the recipient, purpose, credential category, confirmation requirement and expiry.
For example, travel mode could temporarily hide identity, employers, profiles, contribution history, infrastructure and relationships while allowing a narrowly defined proof that the holder satisfies a particular trust requirement. The proof should disclose the claim—not the full evidence behind it—and should avoid a reusable identifier where possible.
“Trustworthy” must remain purpose-specific: identity verified, infrastructure operator in good standing, demonstrated cybersecurity contributor or another clearly defined requirement. TaraSec ID must not issue one universal ranking of a person.
PRIVACY ARCHITECTURE
The preferred architecture separates a minimal identity vault, pseudonymous merit records, infrastructure identities and a holder-controlled credential wallet. Verification material should be deleted when practical after an attestation is issued.
Human identity must remain separated from TaraSec security telemetry and the existing anonymized owner/unit model. A breach of a contributor-profile service must not reveal who generated a traffic or security report.
Future research includes selective-disclosure credentials, holder-controlled keys, rotating identifiers, offline proofs, revocation, recovery, coercion resistance and independent privacy/security review.
A PARTNERSHIP PROJECT
Banks, governments, universities, telecoms, employers, freelance platforms, standards bodies and civil-society organizations all have relevant expertise and different risks to expose.
The proposed first step is a constrained voluntary contributor pilot: jointly define the threat model and ethical framework, issue narrow credentials such as verified node operator, test selective disclosure and independently evaluate fraud, bias, exclusion, coercion and breach consequences.
Discuss research cooperation → Join the public design discussion →