Comment by mindslight

2 days ago

> I don't know why HN rails against it [ZKP for age verification] constantly

Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so. Which means that the only way for it to actually be secure is for the implementation to also required locked down computing devices. Hence why the EU scheme insists on proprietary Apple/Google devices, and why Google research has written nerd sniping blog posts to market it.

There, now you know!

> Because on its own as often presented, it still has the glaring shortcoming that anybody can proxy an ID verification for anybody else without any form of accountability for having done so.

As do physical IDs, as somebody who's bought his younger brother beers growing up.

  • No, that's proxying the service. Presumably if your younger brother had asked you to buy ten handles of pure grain alcohol, you would have asked some questions.

    Proxying the credential means something like letting your brother use your ID. But note there are still avenues of accountability here - for your brother if he would have gotten caught, and possibly for you for loaning him your ID.

    These dynamics don't translate to Internet scale, where all it takes is literally one person to go "I disagree with this age check scheme on principle, and I will proxy my credential to anyone who asks".

    At any rate, you had started off saying you didn't understand why there was criticism and now you know why, regardless of whether you accept that criticism.