Hacker News new | ask | show | jobs
by AlexCoventry 1550 days ago
You can do even better than that. IRU could proxy your TLS connection to the identity provider, and you could prove to IRU in zero knowledge that the decrypted transcript verifies that your age is over some threshold, without IRU ever seeing your age, and without the provider having to run a signature service. Then IRU is the one who signs the attestation on your age.

https://eprint.iacr.org/2020/934.pdf