Comment by croes

1 day ago

Nope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP.

No third part would know how often you use your ID.

Why do people make up problems that are already solved?

OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.

My example is still just as good if the ID holder is complicit.

But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.