Hacker News new | ask | show | jobs
by c0n5pir4cy 2 days ago
The EU actually has a very good, privacy protecting way of doing this based on zero knowledge proofs.

Unfortunately they completely botched it by having the proof-of-concept app rely on Apple & Googles integrity APIs - which a bunch of countries copied.

2 comments

ZKPs may as well just be unencrypted HTTP headers which would be way simpler and easier to implement. All a ZKP proves is that at least one person in the world is over 18.
This is not completely true.

With ZKP, if you make a business out of reselling tokens you get with your own identity, eventually they will see that you use orders of magnitude more tokens than normal people.

So with ZKP it's more difficult to cheat. Not impossible, just less accessible.

They're not ZK if they can do that
Each individual proof is zero knowledge, but downloading a _bunch_ of them is an indicator, yes. There's no real way to work around this with the current ZKP scheme. I'd argue ZKP is, in theory, the least worse option of all current age verification scheme.

My personal opinion is that age verification itself is a bad idea, but if we're going to go ahead with it, I'd much rather we use ZKP for it than the current mess of "upload your passport and picture of yourself to dodgy 3rd parties that likely now have your browsing traffic associated with your real name"...

So the government would impose a maximum limit on the number of porn sites you can visit each day?
Not necessarily, but it would be difficult to justify why you need to access 1000 porn sites every day, I guess?

The point is that if you build a service that sells age verification tokens, you are doing something illegal. And if you start doing something illegal by gathering said tokens with your own identity, maybe it's not the most clever way to do something illegal?

Of course they are. The whole point of ZKP is that whoever gives you the token cannot link it to your identity. So you can get a token with your own identity and sell it to someone else, and nobody will know...

... unless you get thousands of tokens every day and sell them on a website, where suddenly you start leaking information about yourself everywhere. ZKP still did its job: it's not the tokens that link to your identity, it's your behaviour.

The EU app is still shitty and unfixable, because it requires that you send personal information to a third party. The only acceptable and privacy respecting option is self declaration, which doesn't need any ZKP or any other bullshit.