22 ms·
Opening up ‘Zero-Knowledge Proof’ technology
https://github.com/google/longfellow-zk https://github.com/google/longfellow-zk
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- krunck 1y agoAge assurance will be the gateway to government issued(via corporate proxy) internet usage permits.
- api 1y agoTrue, but I'm also not convinced that a ten year old being able to be face to face with hard-core BDSM and incest fetish porn within 40 seconds of opening a web browser is healthy. I don't like this but don't have another solution other than the porn industry self-policing which isn't promising.
- deleted 1y ago[deleted]
- rvnx 1y agoNow take an intentionally extreme opposite (as a thought experiment): if we put death penalty to people who participate in distributing or in relaying such content, could all of that be solved without the “internet pass” and IDing your internet history ?
- treyd 1y agoMaybe, but even this is broken with the internet being international. You'd need a system much more advanced than even the GFW.
- rvnx 1y agoSomehow this work when dealing with pedophile content, so the tech is already active. For example, on Discord, all your messages are scanned for such. On Cloudflare as well (for over 5 years). For now it means they have no interest to remove such content unless coerced or affected by the public opinion. This would destroy all content though, not just for minors. Absurd, but it works, in North Korea (death penalty), Iran (death penalty), China (10 year prison), and also protects victims from rape, or "rape" under financial pressure. The alternative is to let responsibility of the parents to install web filter to their kids, and let others live freely on the internet, without sharing their history or IDing them. In reality, TikTok also has really traumatizing content, yet is engaging tons of kids and teenagers, and IDing won't solve that, but good parents can.
- treyd 1y agoI agree, that does work, but there are parameters which are different that make it worth the tradeoff to police it that strongly, like the size of the audience and the much more severe real harm caused by its production and distribution.
- rvnx 1y agoI genuinely don't know what to think on this :| I just pushed this idea as a "solution" to see what others think, but I don't know. Again perhaps educating the parents about how to educate kids about the dangers of internet, and perhaps a web filter for kids. This is actually one place where AI could be useful, to do dynamic local content classification (instead of a blocklist), especially if integrated directly in Android / iPhone. Like https://support.apple.com/en-us/105121 https://support.apple.com/en-us/105121 but more dynamic.
- trollbridge 1y ago
- api 1y agoAdults should be allowed to look at porn. I don't think it's necessarily good for people, but adults are also allowed to binge drink and smoke and eat ultra-processed foods and a lot of other things that are worse for you than porn. CP is an edge case but that's because it's almost impossible to make CP without abusing children and you could view CP as an incitement to violence -- as incitement to abuse children. Parents should ultimately monitor what their kids do. I have a pi-hole that subscribes to lists with millions of porn domains, but I'm a technical person. Non-technical parents are helpless, and kids can easily access it at friends' houses etc. The industry has not empowered non-technical parents to do this, probably because there's a conflict of interest. Lots of parents would use such options to keep kids off social media, and like all addictive things social media wants to hook them early. (I think kids should be off social media too, but it's not quite as nuts as letting them watch fetish porn.) Porn is different now too. It's worse in a way. Like everything else it's subjected to a pressure to get "edgier" to maximize engagement. So today's porn is loaded with simulated incest, simulated rape, extreme BDSM, etc., things that young children are not equipped to properly contextualize. (Some adults aren't either, but at least with adults you can say it's their fault not the porn's fault. The line cuts differently with children which is why children can't smoke, get tattoos, buy alcohol, get credit cards, etc.) If you want to see the consequence of young kids (mostly boys) being raised with unfettered porn access go visit any women-coded space on the Internet (like Reddit) and search for threads discussing why so many men want to choke their girlfriends. Where did this sudden choking fetish come from?
- rvnx 1y agoI agree with you, at the end I think it could work if we offer to promote better local solutions (e.g. better tooling on iPhone), rather than the server authenticating the user. Perhaps find a way to force Windows / Android / iOS to include such "firewall"/webfilter by default.
- Spivak 1y agoReddit being considered a space for women is the funniest take I've heard in a while. But regardless, you didn't adequately take into account that being choked is one of the top sexual fantasies of women. Whatever explanation you put forth has to also explain why it's also highly desirable to be on the receiving end. The "porn has been giving men violent sexual fantasies" line has existed since before I was born but it always ignores that they're the top fantasies among women too. Among my friend group the more common refrain is women who want to be choked but their boyfriends are uncomfortable doing it.
- wbl 1y agoYou mean like the SF city government? This is stuff that a lot of people enjoy doing and taking photos of. The headquarters of a lot of startups are in what used to be the leather neighborhood.
- mystifyingpoi 1y agoWell, you don't have another solution. That doesn't immediately mean that the one presented in the post is the correct one. Far from it.
- MatteoFrigo 1y agoThe post does not present a solution to that problem. Governments around the world, especially in Europe, have legislated the solution, and the solution they have picked is a privacy nightmare. This post solves the privacy problem, which is strictly better than the status quo. We (Google) do not decide what should or should not be regulated.
- piracyrules 1y ago[dead]
- add-sub-mul-div 1y agoTeen pregnancy rates are down since the mass adoption of the internet, a kid learning a few years early that there exist sexualities other than the default one will affect them much less than losing internet privacy and anonymity for life.
- Spivak 1y agoWhat web browser are you using?! I think this says more about you than about the internet if this is what you're seeing.
- djoldman 1y agoFor kids with a guardian, the answer is enabling and empowering the guardian to control what the child can access. Somehow we've inappropriately shifted responsibility away from parents/guardians in some areas like internet access. In other areas, like letting your kid go outside by themselves, we've criminalized reasonable caregiver actions. It's a wild world.
- trollbridge 1y agoIsn’t that the same argument as “Parents should keep kids away from cigarettes” by tobacco companies who were simultaneously marketing to children? And parents aren’t in control of children 24/7. Schools tend to provide tablets and laptops everywhere, and how much trust should parents have that things like a content filter are adequate to keep children from asking objectionable pornography, hate sites teaching misogyny and so forth?
- djoldman 1y ago> Isn’t that the same argument as “Parents should keep kids away from cigarettes” by tobacco companies who were simultaneously marketing to children? I think most would agree that there's a significant difference between a physical product that shortens the lifespan of virtually all humans who use it, and looking at images and video, no matter how extreme. > And parents aren’t in control of children 24/7. Schools tend to provide tablets and laptops everywhere, and how much trust should parents have that things like a content filter are adequate to keep children from asking objectionable pornography, hate sites teaching misogyny and so forth? Agreed. Parents and guardians should definitely be aware of and concerned about what internet filters are in place at schools.
- _w1tm 1y ago> Parents and guardians should definitely be aware of and concerned about what internet filters are in place at schools. Neither of the words you used give parents any control over the situation. Legislation is the circumspect way parents are exerting control over websites that are unable to police themselves.
- burnt-resistor 1y agoThis is a parenting problem, not a technology and everyone else problem.
- csomar 1y agoThe parents bare the responsibility. Don't baby-proof the Internet, the same way we are not baby-proofing the streets, subways or anything else.
- perching_aix 1y agoAnd maybe also uniquiness guarantees, so that people can finally stop debating whether the internet is "dead"?
- jjmarr 1y agoNot necessary, Uganda has been levying social media taxes on end-users since 2018 by automatically adding it to your cell phone bill if you access a social media website. About 2.7¢ per day of usage.[1] Virtually everyone gets their internet from an ISP that is regulated in the country that the user lives in. There are no technical barriers to implementing a permitting system in the United States. Linking connections to real people is self-enforcing when there is a usage-based tax. [1] https://www.africanews.com/2018/04/13/uganda-s-social-media-tax-amounts-to-repression-of-free-speech-activist// https://www.africanews.com/2018/04/13/uganda-s-social-media-...
- kridsdale1 1y agoVPN or TOR?
- regularfry 1y agoDo you happen to know what the answer of this scheme to "I have a wireguard connection to another country, you can't see my traffic" is? I know that enough of the population would never bother so it wouldn't significantly harm it as a revenue scheme, but if your goal is avoiding identification rather than taxation then the stakes could be high enough to make the effort worthwhile.
- heavyset_go 1y ago> Do you happen to know what the answer of this scheme to "I have a wireguard connection to another country, you can't see my traffic" is? WG traffic is easily identifiable and able to be blocked, it's what happens in countries that ban VPNs.
- prophesi 1y agoAt that point something along the likes of shadowsocks would be more effective, and the question still remains.
- ranger_danger 1y ago
- burnt-resistor 1y agoYep. This is completely kakistocracy-technofeudalism complex enablement.
- mullingitover 1y agoToday it's age gating porn, but the next move will be age gating sites that talk about LGBTQ issues by moving the 'obscenity' definition to be anyone they don't like. Left to their own devices and unopposed, they'll declare discussion of birth control and interracial marriage to be adults-only.
- Jommi 1y agoThats why we need to go even further: https://vitalik.eth.limo/general/2025/06/28/zkid.html https://vitalik.eth.limo/general/2025/06/28/zkid.html
- EGreg 1y ago[flagged]
- MatteoFrigo 1y agoNope, no blockchain involved.
- deleted 1y ago[deleted]
- tucnak 1y agoTo say this has nothing to do with blockchain is like saying RADAR had nothing to do with war. Yes, people knew Maxwell's equations prior, i.e. "knew the proofs," w.r.t. ZKP but it has only really been developed much later, during the war. The whole field of zero-knowledge mathematics was, if not non-existent, but certainly marginalised, before the crypto investment has hit the scene; this is facts. Yes, Shamir et al. go back to 90s, but it's a far-cry from zkSNARK, zkVM stuff we have nowadays. It has also popularized many applications, like provable auctions (see kyber[1] library in Go as nice starting point...) and opened the door to homomorphic stuff. [1] https://pkg.go.dev/go.dedis.ch/kyber/v4/shuffle https://pkg.go.dev/go.dedis.ch/kyber/v4/shuffle
- Kranar 1y agoThe comment didn't say that ZKP had nothing to do with blockchain. The comment said that blockchains are not needed/involved for a zero knowledge proof, just like war is not needed for radar.
- MatteoFrigo 1y agoActually I meant blockchain qua blockchain, that is, ledger and consensus. There is no ledger and consensus at all in this system. If people want to redefine blockchain to mean zero-knowledge, and they want to redefine zero-knowledge to mean succinct as they all seem to have done, it's not my problem. There is no blockchain here, period.
- nielsbot 1y ago[flagged]
- MatteoFrigo 1y agoAuthor (of the code) here. The context is the US mobile drivers licenses and the forthcoming digital identity documents in the EU. The government gives you an electronic document stored in your device, and now the problem is, why would you ever want to give a copy of your document to a third party. This code solves the problem via zero-knowledge presentations of the document. This is real stuff already integrated in Google Wallet, not vaporware. See also the paper linked from GitHub. Ignore the marketing in TFA.
- deleted 1y ago[deleted]
- IshKebab 1y agoHow do you prevent kids just obtaining a copy of such electronic document from somewhere? The actual document itself doesn't prove anything about your age; it just proves that you have the document. Is it stored in a TEE or something like that?
- deleted 1y ago[deleted]
- slwvx 1y agoThe paper linked from Github is at [1]. Section 6.1 gives a fairly practical example of use with a passport, while 6.2 talks about how it might be used with a drivers license. [1] https://eprint.iacr.org/2024/2010.pdf https://eprint.iacr.org/2024/2010.pdf
- deleted 1y ago[deleted]
- cyberax 1y agoThis might enable something like Scroll (the pay-to-view without ads network, acquired and destroyed by Twitter) but anonymous.
- 0xOsprey 1y agoWe're building a purpose built self-custodial payment rail using zero knowledge cryptography that could be leveraged for this use case: https://x.com/0x_Osprey/status/1925299005191577921 https://x.com/0x_Osprey/status/1925299005191577921 https://paygo.wtf/ https://paygo.wtf/ Current benchmarks for proving costs are 33k txns per dollar and we expect this to go down x10-x100 over the coming months/years.
- cyberax 1y agoBlockchain => trash A system that can be trusted needs to work in the real world, with credit card payments, bank accounts, VAT.
- 0xOsprey 1y agoI use a blockchain wallet that lets me instantly switch between "USD in a Bank Account" to "self-custodial USDC on a blockchain" and so can you: https://apps.apple.com/us/app/fuse-solana-smart-wallet/id6470302252 https://apps.apple.com/us/app/fuse-solana-smart-wallet/id647... I can also move the funds into a connected debit card so I can spend it in the real world. This wallet is powered by Bridge.xyz which was acquired for $1B+ by Stripe in Fall 2024 - would encourage you to try the new stuff!
- mumbisChungo 1y agoA fun mechanism for guaranteeing privacy of information in competitive multiplayer settings that operate on distributed networks.
- dcreater 1y agoSo ZKP actually works?
- wmf 1y agoIt has been working for years in Zcash.
- quantumgarbage 1y agoOfc, since approx the 80s
- deleted 1y ago[deleted]
- 0xOsprey 1y agoYes - we've even seen entire virtual machines that allow you to prove arbitrary rust code. Our team is leveraging zkVMs for paygo.wtf
- bobbiechen 1y agoAnyone have a good explanation on the intuition of non-interactive zero-knowledge proofs? For example, I thought the "paint-mixing" analogy for Diffie-Hellman key exchange (https://en.wikipedia.org/wiki/Diffie–Hellman_key_exchange#General_overview https://en.wikipedia.org/wiki/Diffie–Hellman_key_exchange#Ge...) really helped me handwave the math into "mixing easy, unmixing hard". https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/ https://blog.cryptographyengineering.com/2014/11/27/zero-kno... was a good intro for interactive ZK proofs but I haven't been able to find something for non-interactive ones. This blog post comparing ZK-STARKs to erasure coding is in the right flavor but didn't quite stick to my brain either: https://vitalik.eth.limo/general/2017/11/09/starks_part_1.html https://vitalik.eth.limo/general/2017/11/09/starks_part_1.ht...
- supernikio2 1y ago"The Ali Baba Cave" example from the Wikipedia article is what made it click for me: https://en.wikipedia.org/wiki/Zero-knowledge_proof https://en.wikipedia.org/wiki/Zero-knowledge_proof.
- bobbiechen 1y agoThis is an interactive example, isn't it? It doesn't help me understand non-interactive proofs like SNARKs/STARKs, where the verifier isn't communicating live with the prover.
- quantumgarbage 1y agoLook for the "Fiat Shamir heuristic" to understand the non interactive part. It basically consists in the prover getting its random challenges from hashing public inputs, rather than from the verifier's coin tosses.
- bobbiechen 1y agoThank you!! If I understand correctly: * The prover commits to a starting value (public input) * Instead of waiting for an interactive challenge, they hash it and use the resulting hash output as if it were a challenge If we believe the hash is a random oracle (as we do for cryptographic hash functions), then it is hard for the prover to manipulate the challenges. Is that it?
- esbranson 1y agoGood. ZKP is a good way to handle decentralized identity proofs. We can imagine other uses of ZKPs with digital identity wallets, such as proving state political party affiliation for participation in independent e-democracy services without having to provide PII. Good on the Commission for following through on this, not sure we've seen much from them in the protocol space since ISDN.
- natch 1y agoA world can be built on this. So many things are broken privacy-wise because we have to overshare our PII. SSNs for example.
- consumer451 1y agoAgreed. There is a lot of negativity about this here, but on-balance this seems like a great thing.
- Confiks 1y agoIt's a very interesting solution that allows for multi-show unlinkability to be married to hardware binding using existing ECDSA hardware keys. It's not limited to age verification; it can be applied to arbitrary attributes. It's also an unfathomably complex solution [1] which only a few people in the world will grok, and far more complex than existing solutions such as Idemix or BBS+, which lack such a hardware binding on existing hardware. Age verification in a privacy preserving way is a really hot topic at the moment, but it will always be possible to bypass it – as will any commonly held anonymous boolean – in quite trivial ways. For example by setting up an open proxy to disclose genuine attributes. There are some privacy preserving mitigations, for example cryptography that'll make you linkable when disclosing more than k times per time period, or detecting slower-than-near-light-speed disclosure in a face-to-face disclosure scenario. However, these mitigations will never be completely secure. That might not be a problem if it's admitted beforehand so expectations are correctly set: it's a barrier to protect the naïve, not an impenetrable fortress. However, if the expectations are that only age verification that cannot be bypassed is "adequate", we only have to wait for the first incidents in production apps after which the open source and privacy story will be abandoned in the name of security. [1] https://eprint.iacr.org/2024/2010.pdf https://eprint.iacr.org/2024/2010.pdf and https://eprint.iacr.org/2022/1608.pdf https://eprint.iacr.org/2022/1608.pdf
- MatteoFrigo 1y agoOn the contrary, any undergraduate can understand our solution. In contrast, I don't know anybody who can explain the bilinear pairing in BBS.
- Confiks 1y agoPerhaps "unfathomably" was too strong, but "any undergraduate" is at least very easy to falsify.
- MatteoFrigo 1y agoJokes aside, I really believe that once all is said and done our system is way simpler than BBS. How are you going to check the document expiration date in BBS? Yes I know about range proofs, I know about the quaternion norms and the four prime theorem and all that jazz. But nobody is talking about it. How are you going to bind to a hardware secure element that only uses NIST primes? Yes, there is a very clever variant called BBS# which I believe works, but that's not simple either. How are you going to deal with existing standard formats? 80% of our complexity is in this step. BBS most likely cannot do it at all. If we can change the format then a lot of my complexity disappears too. How are you going to deal with the fact that BBS signs an array and not a set, and thus you are leaking the fact that "family_name" is attribute at array index 42? Are you going to leak the schema (which re-introduces tracking) or are you going to agree in advance, now and forever, on a schema? (Our system hides the schema and works on an arbitrary key/value dictionary, up to a maximum size.) It's easy to say "simple" when one has not built the real thing.
- weinzierl 1y agoSparkasse is not a word I had expected in a post like this, but here we are. The Sparkasse network is not very well known outside of Germany but is actually Europe's largest financial services group by assets. What is interesting is that until the 90s the membership banks were public institutions backed by municipal and state guarantees that made them virtually bankruptcy-proof, unlike private banks. EU competition rules then forced Germany to phase out these state guarantees, making Sparkassen subject to normal banking regulations and deposit insurance like other banks. https://en.m.wikipedia.org/wiki/Sparkassen-Finanzgruppe https://en.m.wikipedia.org/wiki/Sparkassen-Finanzgruppe
- deleted 1y ago[deleted]
- vvpan 1y agoA cool technology that builds on ZK is zkTLS that can prove that you have access to some data on the internet, for example that you have an account with some service without revealing your username. So more private oauth I suppose?
- EulerLagrange 1y ago[dead]
- TuretzkyRon 1y agobut the server side does not have to support it on their end for it to be used
- Sancty 1y agoI'm excited for this to be mainstream. OAuth is definitely a step in the right direction, but many times scopes are broader than they need to be and can be abused. AFIAK, zkTLS can provide derivate values; i.e "You are over 18" (T/F?) verse "Your birthdate is".
- dop42069 1y agoIt works for private user data in adversarial setting. Like the outcome of a rocket league match can settle a $20 bet. Showdown.win
- tucnak 1y agoThis is perhaps more important in the age of AI agents, but before we can tackle all these fancy ZKP constructs in the mainstream — we have to, as the industry (and so far consistently failed to) — implement Zanzibar, or whatever ReBAC, and maybe ZKP stuff could "sneak in" that way, in the form of zero-knowledge warrants, or whatnot. Unfortunately, even though it works consumption-wise, it's fundamentally at odds on the provider side. The providers are clutching their OLAP like pearls! :-)
- baby 1y agoGreat intro to how zkTLS works: https://blog.zksecurity.xyz/posts/zktls/ https://blog.zksecurity.xyz/posts/zktls/
- ChuckMcM 1y agoThis is great. It really pissed me off when David Chaum locked all the cool uses of ZKPs behind a patent wall. The DigiCash folks were peak dot com greed types, their business model was "We're going to get big chunk of change out of every transaction ever so we should be valued at 1% of the worlds GDP!" And the world responded with "Yeah, no." I really like Andy Birrells "micro-cents" which exploited the fact you could not easily reverse an MD5 hash so you one could cheaply do high confidence low value transactions at speed. Another idea that never got anywhere sadly. ZKP ID cards and ZKP currency are both interesting things from the 90's I'd love to see in real life. Imagine I could pay you phone to phone with no network level of capability using a currency that couldn't be double spent. That was the promise of digicash. The government hated it :-). It was just like cash currency in that serial numbers could let you track the bank it left, and the bank it came back in to, but you couldn't track anywhere it had been between those two points. Fun times. I'll have to see if some of my ZKP ideas can be built on top of this tech now.
- 0xOsprey 1y agoHere is one we are working on: https://paygo.wtf/ https://paygo.wtf/ https://x.com/0x_Osprey/status/1925299005191577921 https://x.com/0x_Osprey/status/1925299005191577921
- coldpie 1y ago> This is great. Do you still feel that way knowing that it introduces a hard requirement for all users to have their private data managed by one of Apple, Google, or Microsoft[1]? I want to be excited about this, and about Passkeys, but the people working in this space keep fumbling this ball :( [1] "Using the MDOC requires a signature from a hardware security key in the phone" https://news.ycombinator.com/item?id=44458417 https://news.ycombinator.com/item?id=44458417
- baby 1y agoFor people interested in zero-knowledge proofs check https://news.zksecurity.xyz/ https://news.zksecurity.xyz/ which is a hackernews but for ZK!
- WXLCKNO 1y agoIt's interesting how painful that design is to my eyes compared to the HN home page, I can't say why at a quick glance it's just hard to parse for some reason / doesn't feel good.
- Labo333 1y agoVery interesting in the context where major porn websites blocked access in France (now reverted) and in some US states as a response to age verification regulations that were too difficult to implement without compromising user experience and privacy.
- csense 1y agoHow do you defend against someone who: - Buys or borrows a laptop / phone / whatever from somebody with an authorized private key - Downloads an authorized private key file from a sketchy forum (maybe hacked from an unwilling target, maybe willingly shared by a free-speech advocate) - Uses a VPN over HTTPS to visit websites in countries where age checks aren't legally mandated (and non-compliance is implicitly or explicitly encouraged for economic or ideological reasons)
- MatteoFrigo 1y agoThe credential ("driver's license") contains a public key whose secret key is stored securely in a hardware secure element. The standard assumption is that the SE is in the phone, but it could be a yubikey or similar device. In order to use the credential, you need the SE. So you cannot buy a phone from somebody and download a credential from somebody else. You can however buy a phone and the credential from somebody. As a mitigation, the SE only generates the signature when unlocked via a fingerprint or similar biometric input which must match the one that was provided at the time the credential was issued. Whether or not your attack works in this scenario depends on the details. For example, if you only obtain the credential in person at a local government office and provide a fingerprint at that time, it's not that easy to sell the phone and the credential afterwards.
- deleted 1y ago[deleted]
- ranger_danger 1y ago> the SE is in the phone, but could be a yubikey or something else Just like with passkeys or MFA, the "something else" could be purely software though, right? And hence automated? For example I can run Windows 11 in a virtual machine on Linux, using softu2f to emulate TPM 2.0, and Windows does not know the difference.
- MatteoFrigo 1y agoThe problem that needs to be solved is, how can a government give you an identity document in a way that you cannot give the document to somebody else. Whether or not this problem needs to be solved is a political question, but it seems like the majority thinks that identity documents should be hard to forge, in the same way as dollar bills should be hard to forge. The only practical solution is to have some sort of hardware that the user cannot forge, and relying parties will insist that the document be bound to such hardware. So yes, the something else could be software, but nobody will accept signatures from an emulated TPM. I had in mind a government-issued yubikey that can be identified as such, or maybe a plastic card with embedded secure chip with the same functionality. See https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework https://github.com/eu-digital-identity-wallet/eudi-doc-archi... for the current thinking at least in the EU. I should also remark that the above is a western-centric perspective, whatever "West" means. For example, I heard the architect for a similar system already deployed in India remark that in his jurisdiction many households share one phone across many family members, and India chose to accept more possibility for fraud in exchange for wider usability by the population. In that context this choice looks like the correct solution.
- hrdwdmrbl 1y agoCan someone compare their tech to the current research frontier of ZK-p tech? The reason I ask is that I know that many teams working in the b-word field are _regularly_ making great progress. So I'm just wondering if this work is actually novel / useful or whether it's Google releasing something that is already stale.
- MatteoFrigo 1y agoAs the Google guy who did the system, I really don't want to engage in this discussion. I'll just say that the b-systems solve a different problem, and for the problem solved by our system there is currently no other solution available. We spoke with Ying Tong and her colleagues from the Ethereum foundation. They have a project investigating which ZK technology would be best for digital credentials, and they have ran a few benchmarks at https://hackmd.io/@clientsideproving/zkIDBenchmarks https://hackmd.io/@clientsideproving/zkIDBenchmarks For reference, our implementation runs the benchmark in about 200ms on the same hardware. The ETHF folks have had access to our code for a while and they agree with this result, but they decided not to publish numbers until the Google code was open-sourced for all. Our system is thus about 10x faster than the closest contender for this problem. I don't want to make any general claims about who is better than whom. Our system is designed for our problem, and it's not a surprise that another system designed for another problem would perform worse on our problem. We are big fans of the Binius system of Diamond and Posen at Irreducible, and there is a chance that Binius may eventually work better than our stuff. That's however not the case today. You also have to be careful about which hardware to use. Our implementation is single-threaded no GPU because it has to run on all phones everywhere in the world. Whether or not one can do better on a high-end GPU is irrelevant to us. Either way, "stale" is not a word I would use. The word I would use is "works today".
- a_tartaruga 1y agoBlockchain people consider Ligero as a modern construction worth using. At least last I checked 6 months ago. This work isn't reinventing the wheel and appears to be targeting a nice problem in service of a practical system. The author's country of origin also makes the work seem more legit because everyone knows Italians are the best at zk.
- ranger_danger 1y ago> In layperson’s terms, ZKP makes it possible for people to prove that something about them is true without exchanging any other data. So, for example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all. But how does it prove that the request is actually made by a person and not a bot? Surely that part is technically impossible right now?
- MatteoFrigo 1y agoThe government gives a signed document to natural persons, and the ZK system proves that the document is signed by the government. Bots don't have passports or driver's licenses. How does the government guarantee that the natural person is such? Various jurisdictions will decide what's good enough, but as a strawman proposal, you go in person to city hall once and upload a document to your phone.
- ranger_danger 1y agoThat might prove the token itself is legit, but still doesn't prevent a bot from using it, right?
- est 1y agoAnyway to verify an email address is valid using zero-knowledge?
- endorphine 1y agoIsn't it a pity they did not choose a safer language?
- BimJeam 1y agoFor the sake of sanity - do never rely on Google when building critical sections of your software!
- Ey7NFZ3P0nzAe 1y agoGood thing it's open source
- andy_ng 1y agoI wonder will the final report and any addressed CVEs be publicly documented, and is there a plan for ongoing third‑party audits to build trust in long‑term usage?
- randomNumber7 1y agoI'm so tired of old closed minded people that run EU countries since ever. I know someone in germany that got detected cancer in an MRI scanner. The doctor gave him the images and told him to drive to a specialized hospital ~400km away. Otherwise they would send it there with a physical mail and the treatment would have started a week later.