Comment by croes

2 days ago

add MFA to the check

add a different ID check to the MFA if that doesn't work, then add more MFA to that new ID check. Eventually it has to work, right?

It's definitely worth doing infinite security in order to avoid regulating social network algorithms, because

  • To prevent abuse add MFA to the ID. Problem if stolen cards solved and still zero knowledge.

To where, the site requesting the verification? Now it is no longer zero knowledge.

  • No, to the ID to prevent abuse if the card get stolen.

    • Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key.

      The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.

      Your system effectively collects exactly the data ZKP is intended to protect.

      Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.

      2 replies →