|
|
|
|
|
by amanagnihotri
1593 days ago
|
|
OAuth 2.0 resolves this. The government can be in control of maintaining citizens' identities and citizens can likewise request claims from the government's auth server regarding their age or any other matter. That claim as a signed message can be provided to third-party services which need only validate the signed message using the public key associated with the secret key that signed the claim message. |
|
How would the flow go? Click on an age verification link on a site. It redirects to the gov site, where you authenticate and it returns a signed claim.
Now the government knows what sites you are visiting. Not something I suspect most people will want when accessing porn sites...