Comment by Spivak
2 days ago
Which means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key.
The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway.
Your system effectively collects exactly the data ZKP is intended to protect.
Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.
Nope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP.
No third part would know how often you use your ID.
Why do people make up problems that are already solved?
OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.
My example is still just as good if the ID holder is complicit.
But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.