Hacker News new | ask | show | jobs
by coppsilgold 51 days ago
It seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed.

Also, remote attestation doesn't work that way and for good reason. Under a true ZKP system, a single defector (extracted/leaked/etc key) would be able to generate an infinite number of false attestations without detection.

2 comments

> It seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed

This article is about EU age verification which is specifically and definitely stated as using zero knowledge proof in all technical docs that I've seen:

https://eudi.dev/2.5.0/discussion-topics/g-zero-knowledge-pr...

In that case Google play integrity cannot be used.

It certifies devices running on Oreo (because vendor didn't provide updates),meaning there are almost infinite vulnerabilities that will allow to leak the keys.