← Back to context

Comment by vrganj

2 days ago

This is precisely why the authority doing these checks needs to be the government that already issues the IDs.

Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.

I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.

> I don't know why HN rails against it [ZKP for age verification] constantly

Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU scheme insists on proprietary Apple/Google devices, and why Google research has written nerd sniping blog posts to market it.

There, now you know!

  • > Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so.

    As do physical IDs, as somebody who's bought his younger brother beers growing up.

    • No, that's proxying the service. Presumably if your younger brother had asked you to buy ten handles of pure grain alcohol, you would have asked some questions.

      Proxying the credential means something like letting your brother use your ID. But note there are still avenues of accountability here - for your brother if he would have gotten caught, and possibly for you for loaning him your ID.

      These dynamics don't translate to Internet scale, where all it takes is literally one person to go "I disagree with this age check scheme on principle, and I will proxy my credential to anyone who asks".

      At any rate, you had started off saying you didn't understand why there was criticism and now you know why, regardless of whether you accept that criticism.

Government systems leak information all the time. The type of institution managing the data makes little difference. Its how the institution manages the data that matters.

  • But the government inherently has that data, as it comes from there. They're the ones issuing the IDs in the first place.

    Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.

    • All previous systems avoided this. The government issued me an ID in the past, yet had no record of when I used it, or for what.

      I am so much more afraid of monopolies invading my privacy than roving hackers, or my corner store. Governments are the ultimate monopoly.

      1 reply →

    • I think the point is that if I have to use some system to tell the government "this is me", that's pretty much equivalent to the ID. It doesn't matter that they have the info already, it's that I now need to send them it in order to use the internet to like, file my taxes or send a message to my doctor or pay my electricity bill or any number of mundane things that aren't particularly worth the extra attack vector to try to protect against.

      2 replies →

It is European which means that it is both anti-capitalist and communist and therefore must be spit upon.