Hacker News new | ask | show | jobs
by YourDadVPN 38 days ago
The EU's proposed system uses ZK proof. You get a PGP signed message from "someone" who knows your identity (government or private agency) then store it on your phone to pass to websites that need your age. It does have an obvious flaw in that whoever you give the token to has no proof it's actually yours.

https://ageverification.dev/av-doc-technical-specification/d...

2 comments

> It does have an obvious flaw in that whoever you give the token to has no proof it's actually yours.

Which isn't necessarily a flaw, depends on the threat model. For actual age verification that we care about (e.g. make it harder for kids to access social media), it may be good enough.

This is not sufficient. Do they give you a blind signature?

Because what you described does not preserve your anonymity if the government and the service collude.