3 ms·
There are solutions like Yivi[1] (previously IRMA) that allow you to have a wallet of attributes signed by federal or local government (eg. "user is over 13" or
by Manfred 3y ago
There are solutions like Yivi[1] (previously IRMA) that allow you to have a wallet of attributes signed by federal or local government (eg. "user is over 13" or "user lives in Wisconsin"). That way you never have to share your identity, just certain attributes that are specific to the use-case.
[1] https://www.yivi.app/en https://www.yivi.app/en
- endisneigh 3y agoEven with that it would be trivial to uniquely identify specific individuals. If anything that would be worse than the current situation as you would know certain attributes are definitely not spoofed.
- robcohen 3y agoWith zero knowledge proofs, no it won’t be trivial. Because it will be binary as opposed to identifier based.
- endisneigh 3y agoNo, because it would be widely known what information is collected and what information is given in a verified fashion. How exactly would you prevent leaking?
- LinuxBender 3y agoAre those attributes reversible to an index of real PII? Asking because these things all seem to oopsie leak or get sold or hacked or turn out to be sitting in a public S3 by mistake eventually. How does the site know that I am using my wallet attributes and not someone else's?
- htag 3y agoIt looks like the answer is yes 1. These 'digitally signed attributes' (example: 'age: 19') are consistent across services. So if you attribute is leaked in a way that it connected to other PII, then everyone with the attribute will know your PII. 2. These attributes are generated by a central authority. Presumably the goal would be to have governments issue these attributes. Regardless, whatever verification you do with the central authority will reveal your identity, and they can always determine your PII from the attributes they created. [0] https://irma.app/docs/what-is-irma/ https://irma.app/docs/what-is-irma/