Comment by deltoidmaximus

2 days ago

To where, the site requesting the verification? Now it is no longer zero knowledge.

No, to the ID to prevent abuse if the card get stolen.

  • Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key.

    The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.

    Your system effectively collects exactly the data ZKP is intended to protect.

    Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.

    • Nope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP.

      No third part would know how often you use your ID.

      Why do people make up problems that are already solved?

      OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.

      1 reply →