← Back to context

Comment by vasco

15 days ago

If the input is "give ID", what the software claims to do is almost meaningless since you cannot prove that software was running. What do I care that someone can tell me they built a privacy-first way of validating IDs/age if I cannot be sure that is the software they are running?

They can just as easily save the ID to disk and return "all good" for all I know.

No, the solution does not require that.

It requires that Bob proves posession of a private key, that only he has ever had. That private key could be generated specifically for the commitment that he got from Alice.