Hacker News new | ask | show | jobs
by Tadpole9181 876 days ago
Er... The CA needs to be used to verify the certificate by the third party, ergo it will know the websites.

It's virtually impossible to make a verification system that's anonymous. Somewhere the third party and authenticator will need to share a secret that you cannot touch.

Furthermore, you would need the government to agree to this system and mandate this system universally and pay for the authentication services to exist. That's not what Florida is doing.

1 comments

I can show my government-issued ID to any third party without the government knowing about whom I've shown this ID to. The third party needs to trust the government and the authenticity of the ID.

The problem is that my ID contains too much information; I would prefer a document (i.e. digital certificate) that only certifies my age, not my name, address etc.

Any such ID would need to be validated by the service. Therefore the service and the authenticator would need to speak. And in doing so, the authenticator will be able to see that an ID issued to you is being used for that service.

You cannot get around this. The service must confirm with the authenticator. The authenticator must know you are authenticated, and be extension, who you are.

Your comment is incompatible with mine, so one of us must be incorrect; I will leave it at that.