8 ms·
Google Wallet launches new age and identity verification features (ZK proofs)
- holowoodman 1y agoTheoretically, using zero knowledge proof for age verification is a great idea. Too bad that while the porn website you are visiting will not get your name from google, google will sell the fact that you visited that porn website to anyone who is interested...
- arealaccount 1y agoIf you're using Chrome, which most people are, I'd assume this is the case anyway? Note - agree with your sentiment.
- tmoertel 1y ago> google will sell the fact that you visited that porn website to anyone who is interested. Has Google has actually done this? According to Google, they don't sell personal information: https://about.google/company-info/how-our-business-works/#:~:text=We%20don't%20sell%20your,ads%20based%20on%20your%20interests. https://about.google/company-info/how-our-business-works/#:~... I'm willing to believe they've broken this promise, but if you can point to some actual proof, I'd like to see it.
- kmeisthax 1y agoGoogle does not sell personal information, they rent it out. Targeted advertising and remarketing relies upon building up a huge dossier on each Internet user and then matching those dossiers to ad bids.
- 3984574 1y agoLook up real-time bidding. Some context: https://www.classaction.org/news/google-breaks-user-privacy-promises-billions-of-times-every-day-through-real-time-ad-auctions-class-action-says https://www.classaction.org/news/google-breaks-user-privacy-...
- tmoertel 1y agoI read it. It doesn't seem to show that ”google will sell the fact that you visited that porn website to anyone who is interested.” What am I missing?
- 3984574 1y agoFrom Google's OpenRTB spec (https://developers.google.com/authorized-buyers/rtb/openrtb-guide#site https://developers.google.com/authorized-buyers/rtb/openrtb-...): > Site > This object is present in the bid request when the impression will be rendered on a website rather than a non-browser application. Contains a "page" field: > URL of the page where the impression will be shown with URL parameters removed. EDIT: If you don't think that counts as personal info then that's that, just trying to prove GP's claim that Google will happily tell a bunch of advertisers that you're visiting a porn website.
- ffsm8 1y agoAccording to that description, it only shows that someone has visited a porn website, not you. This kinda invalidats the claim that Google is selling this information about you
- whimsicalism 1y ago"sell the fact that xyz" can this phraseology die? this is not what these big companies do. they sell attention, not data.
- ajsnigrutin 1y agoThey sell data too, if the governments wants the data, they even give it out for free.
- guerrilla 1y agoWrong, they sell your activity too. Seems like your information on this topic may be significantly out of date.
- whimsicalism 1y agohow do they "sell your activity"
- guerrilla 1y agoIf you wanted to know, you would know. It's not exactly a secret. Here you go though: https://www.eff.org/deeplinks/2020/03/google-says-it-doesnt-sell-your-data-heres-how-company-shares-monetizes-and https://www.eff.org/deeplinks/2020/03/google-says-it-doesnt-... > Real-time bidding is the process by which publishers auction off ad space in their apps or on their websites. In doing so, they share sensitive user data—including geolocation, device IDs, identifying cookies, and browsing history—with dozens or hundreds of different adtech companies.
- incompatible 1y agoThe demonstration, UK railcards, is a bit odd. I thought they were sharing too much information, date of birth when only something like "under 18" would be needed. But these railcards have several different age-based options. What is the point of this age discrimination, surely you take up one seat on a train regardless of your age? Per https://www.railcard.co.uk/ https://www.railcard.co.uk/
- jagger27 1y agoThe Railcard website you linked is pretty clear. > For those aged 16-25, save 1/3 off rail fares for days out, seeing family and friends and even festivals! > For those aged 60 and over, save 1/3 off rail fares for days out, holidays, seeing family and friends, and theatre trips! So, provide proof of age via ID and get a discount. It's very common on public transit for the young and elderly to get a discount.
- incompatible 1y agoand the 26-30 Railcard, and the Children aged 5 to 15, and the for those aged 16 or 17, it just seems weird to have all these age-restricted options for exactly the same product (a seat on a train.)
- jagger27 1y agoCall it woke or socialism, but perhaps it's within a society's interest to make travel affordable for people who don't necessarily have access to other modes of transit. It's the difference between equality and equity.
- incompatible 1y agoI'm not sure that age is the biggest factor in wealth inequality. I could be wrong, but there are plenty of rich kids and poor middle aged.
- trollbridge 1y ago
- btown 1y agoI have mixed feelings about a world where zero-knowledge-based ID verification gets so good that it reduces barriers to being adopted widely. On the one hand, it's better than a world where non-privacy-respecting ID verification becomes required anyways, and thus every bit of your online behavior becomes tied to your actual identity. On the other hand, the presence of this kind of technology makes it easier for governments to say things like "all ___ content online must be restricted to ages 18+ or 21+" and actually have a way to implement that across Discord and TikTok and gaming chatrooms and everything inbetween, in a way that has already been deployed at scale... because it had not already been fought against from a privacy perspective when it was deployed for things like public transit. The things that can be placed in that blank are far more widespread than one might initially think.
- trollbridge 1y agoAnd it sounds like a complete nightmare when you're one of those people whose Google account gets suspended for some random reason, with no appeal process and no way to contact actual customer service. Now you don't have any ID either, and can't prove who you are.
- Beijinger 1y agoWell, what is the difference to today even if you can proof who you are?
- ranger_danger 1y agoyour ID would not be tied to the whims of a corporation
- lmm 1y agoThe difference is that as much as being cut off from Google sucks today, right now it doesn't mean you also e.g. lose access to your digital porn library that you paid for.
- 1y ago
- aaron695 1y ago[dead]
- jillyboel 1y agogross and blatantly illegal under dutch law. companies don't need a copy of my id. most of them don't even adhere to the law anyway and demand an uncensored copy. every time I follow the instructions from my government to blank out the BSN (SSN) the (usually american) company rejects it and demands an uncensored version they're not even permitted to have. https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/vraag-en-antwoord/fraude-voorkomen-met-kopie-id-bewijs https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/v... Last time I checked Google isn't any of the following: * a government instution * a bank * a notary * a casino * my life insurer * my employer https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/vraag-en-antwoord/ben-ik-verplicht-om-een-kopie-van-mijn-identiteitsbewijs-te-geven-aan-een-bedrijf https://www.rijksoverheid.nl/onderwerpen/identiteitsfraude/v...
- wbl 1y agoWhy do you think Google "gets" data in Google Wallet?
- cogman10 1y agoI honestly think this is a bad/dumb idea. Age verification in general is just silly on the internet and laws mandating it are inane. The main thrust of such measures is "Let's make sure a kid can't see/access this". However, without an actual camera to double check that "yes indeedy, this really is the person attached to the ID" then "faking" it is all too simple. I can almost guarantee you'll get IDs floating around the internet which kids will use to completely bypass these protections (or they'll simply swipe their parents' ids when they aren't looking). It's a half step above "what's your birthday" checks.
- warkdarrior 1y agoToo true. The better option is for each computing device with internet access to continuously do a biometric scan of the user (fingerprint, retina, face, etc) and check against a government controlled database that stores identity info.
- cogman10 1y ago:D If perfect law enforcement is the end goal then yes, that's the better security approach. Now, I (and I assume you and most people) don't value perfect law enforcement. I certainly value my privacy more than I value "catching bad guys" or keeping kids from seeing a trailer for an M rated game. That's why I'm calling the idea dumb. It won't work and the next steps to make it work better are horrifying. It's better if we didn't even try.
- knowitnone 1y agoeven if kids stop visiting porn sites, there are many other ways of downloading porn and what they will download will be even worst
- stavros 1y agoThis is going to be a disaster. Societies rely on imperfect enforcement of the law in order to progress. There's no way to create a critical mass of resistance and disobedience that will lead to the toppling of an unfair law if you enforce the law perfectly and universally, and this will lead society to ossify. Imagine if every single gay person were caught and put in jail the moment they acted on their urges, or every single person who bought or sold weed (or alcohol, during the prohibition) were similarly arrested. We'd still be stuck in the mindset of a century ago. A society that has removed its own ability to progress is truly a horrifying prospect.
- fidotron 1y ago> Societies rely on imperfect enforcement of the law in order to progress. This is quite a leap. Societies would be perfectly capable of evolution as long as they are not totally convinced of their own perfection at any given moment. It is quite possible to have everyone follow a law while simultaneously supporting changing it.
- stavros 1y agoDo you have any such examples?
- protocolture 1y agoYep, every society believes itself perfect (or about to become perfect with just one more law), and then 10 minutes later is proven hilariously wrong.
- ryandrake 1y ago> Societies rely on imperfect enforcement of the law in order to progress. There's no way to create a critical mass of resistance and disobedience that will lead to the toppling of an unfair law if you enforce the law perfectly and universally, and this will lead society to ossify. Don't worry, it won't be perfect and universal. Politicians, the police, and their friends and family will surely make themselves exempt.
- charcircuit 1y ago
- motohagiography 1y agothe main thing that has saved the west from digital ID so far has been android OEM fragmentation, where there just hasn't been a way to manage hardware secrets in a way consistent enough across devices to be pushed down on people as a digital ID. this thin edge of the wedge age verification solution is to normalize people showing ID everywhere and whether it's their age or some other social credit attribute is immaterial. the product is submission. the original hope for this was first in differential privacy, then ZKSNARKS, then FHE, and whatever proof they're on about now is intended to obfuscate not the data, but the actual use case, which is going back to covid era ID checks. for climate, surely. I distinctly remember a conversation I had in 2013 while working on early instances of a related identity tech, where I said to the founder and CTO, "nobody wants this, it's something you want to impose on others. your security model needs a failure mode other than catastrophic because the incentives to take it down are tremendous- from fake ID and fraud to people like me who just think you're assholes." Identity isn't a tech problem, it's a political problem people in bureaucracies who problematize human freedom and dignity keep trying to bully through with increasingly obfuscated tech. for googlers reading this though, I've got a great name for your identity product: holler-it! it's just like hollerith but so much quirkier and safe feeling.
- cypherpunks01 1y agoCan anyone explain a bit more about how this actually works in context here? Do you hand your full PII "private key" or equivalent, to Google, or does any of the proving happen on your own device? Then proofs are constructed to 3rd parties, proving certain properties of your data without revealing the underlying data? Are they live/interactive proofs or can static proofs be constructed for these type cases? What is exactly being proved? Proving that you/Google knows a "private key" that can be found in a particular set of public keys published by the issuer? Or something like that?
- krackers 1y ago>which will use digital IDs from Google Wallet to verify user identity and ZKP to verify age This seems to imply you have to upload your information to Google first. But if you do that then what's the point of ZKP, Google might as well just send over a signed attestation token.
- ranger_danger 1y agoThe whole thing is pointless for privacy IMO because it requires a google account, which they can revoke at any time for any reason, not to mention creating one in $this_year already requires way too much personal information.
- danielheath 1y agoAFAICT, Google have the internal culture/belief that "User privacy" means "only Google hold user data, since we're sure we are trustworthy". At least, reading their claims with that in mind has often helped me to make sense of the various claims they make.
- MatteoFrigo 1y agoSpeaking as one of the implementors of the ZKP system described in the article. The identity document (e.g. driver's license) is granted by an issuer (e.g. department of motor vehicles) and stored in the user's device only. Google is not part of this flow and the document is not sent to Google or stored by Google. In fact, one major technical problem is how to make sure that the document cannot be used without having possession of the phone. To this end, the document is associated with the phone's secure element (think of a hardware yubikey already present in the phone itself) and cannot be used without the secure element. Think of the document as a dictionary { "name": "foo", "address": "bar" ... }, although the reality is more complicated. One standard for these documents is ISO/IEC 18013-5, but other possibilities exist. The proof itself proves the truth of a certain predicate on the document. The predicate is something like "The document parses correctly, it is bound to the device's secure element, and it contains zip_code = 012345". The phone generates the proof at presentation time in about 1s. Another major technical difficulty is that past attempts at solving this problem required prover time of tens of seconds. Our proofs have the property that no entity, including a future quantum computer, can learn anything from the proof other than the predicate is true. See https://eprint.iacr.org/2024/2010 https://eprint.iacr.org/2024/2010 for the gory details. The specific predicate being proved is in Algorithm 10. When you say "interactive" you probably mean "at presentation time", as opposed to "in advance". We generate a fresh proof at presentation time and not in advance. Be aware that the ZKP literature uses "interactive" in a different sense, in which the verifier keeps posing multiple challenges to the prover until the verifier is satisfied that the proof is correct. Our system is derived from an "interactive" protocol in this technical sense, and transformed into a "non-interactive" prover via a general transformation called "Fiat-Shamir". The net effect is that the verifier asks "tell me your age and nothing else", the prover sends one message with the proof, and that's it.
- Workaccount2 1y agoWe have the results of what happens when kids grow up with no actual age verification on the internet or with video games. Nothing. Nothing happens. Millenials grew up on the internet where ID checks were "Promise you are 18", and what bad has come of it? A generation of murderers and rapists? Please...
- 3984574 1y ago> We have the results of what happens when kids grow up with no actual age verification on the internet or with video games. A mental illness epidemic? [0] [0] https://www.afterbabel.com/p/the-teen-mental-illness-epidemic https://www.afterbabel.com/p/the-teen-mental-illness-epidemi...
- Macha 1y agoAmongst gen z, who were more restricted than millenials
- ipdashc 1y ago> who were more restricted than millenials I don't think this is true? Generations seem to be getting Internet access at younger and younger ages and the Internet takes up more and more time in our lives with every passing year, and Phones Bad / Social Media Bad seems to be a pretty commonly accepted concept.
- Macha 1y ago- No site asked me for credit card numbers at 14 to prove I was 18+. - The person who operated our house's tech infrastructure was me, since my parents were too technically illiterate to do it. And it took operating in these days, rather than the relatively one stop wifi boxes of today. - Parental filters, where they existed, could be defeated with a simple alternate DNS server. - I was also just allowed be unsupervised in general for way longer than gen Z or alpha kids are allowed. My country hasn't quite gone to the same "a child in the wild, call CPS" levels as some parts of the US has, but certainly the average child now is more limited than they were in the 90s So yes, gen alpha kids have phones. But unlike when I first got a laptop and could do basically anything on it, the phones these days are much more locked down, and by the OS manufacturers who actually try to plug holes as they're discovered.
- o11c 1y agoIf Google only does this when you tie your identity to a real-world ID, and refuses to auto-grant it for people whose accounts are more than 18 years old, then this is just a data heist. For reference, 2007 is 18 years ago.
- the__alchemist 1y agoLet's say I set up my ID with this. Next year, when Google Wallet is replaced by Google Money, will the ID transfer? Will it have this feature still?
- bitpush 1y agoBetter than Apple Intelligence which put the cart before the horse.
- ikiris 1y agoNah it would be called Google Wallet Money Duo. Google Wallet will keep working for 6 months. Then stop. Around the same time Google Money Wallet will launch. Neither will support credit cards correctly for another 6 months. Then Google Billfold will launch...
- zb3 1y agoNot good.. yet another thing that will not work on devices with unlocked bootloader.. I hate how smartphones with preinstalled spyware are becoming necessary..
- jauntywundrkind 1y agoGoogle can open source some libraries here, but to what ends? Ultimately there is not zero knowledge here, there's one very concrete bit of information: Google says so. Sure other people might be able to replicate the signing process. But who else is going to be able to get governments around the world to add those other would be zk proof providers? This feels like such a vicious demented technological gordian knot being woven to trap humanity in. Meanwhile the web has it's own devilry in progress, a similar effort to make non authenticated people utterly unable to use the web, the Digital Credentials API, brought to you again by Google. https://developer.chrome.com/blog/digital-credentials-api-origin-trial https://developer.chrome.com/blog/digital-credentials-api-or... This is all so hideously bad for humanity. The zero knowledge aspect is the absolute bare minimum to not make this pure scum and villainy, but it's still a sick awful thing to do to humanity, uses a lure of convenience to walk us into a place where the individuals of the world are powerless and where ever expanding digital dominion over us corals and steers us. Do not want, go back to hell & stop trying to drag hell to earth, monsters.
- deleted 1y ago[deleted]
- whoomp12342 1y agothat AI voiceover is downright embarassing. I expect better from the likes of google.
- waltercool 1y ago[dead]
- robdefeo 1y ago(Disclosure: I’m the CTO of Vidos, a company building such an identity layer.) I believe in a version of the trust triangle. Where issuer, holder, and verifier remain clearly separated. Meaning no single entity, has full control over your data. E.g. a government issues an ID credential to your wallet app, and you can use it to prove your age without any intermediary getting any extra data. The site gets a cryptographic proof “user is 18+” and nothing more. I'm pleased when I read standards like ISO 18013-5 for mobile IDs that support selective disclosure by design. You share just a yes/no or an attribute, not your whole ID document. Crucially, this addresses the “Google as a single point of failure” fear. You just need credentials from issuers you trust (your government, your bank, university, etc.) stored in a wallet of your choice. The verifier (website/app) will accept a proof from any wallet/issuer that meets their criteria. We’ve built our system to be agnostic about credential sources for exactly this reason. It’s a universal verification layer. If anything I hope we can agree, we must continuously surfacing and discussing these risks early rather that waiting until it's too late.