4 ms·
There is a correct way to do age verification (and information verification in general) that supports strong privacy and makes it difficult to evade: https://n
by Edmond 11mo ago
There is a correct way to do age verification (and information verification in general) that supports strong privacy and makes it difficult to evade:
https://news.ycombinator.com/item?id=44723418 https://news.ycombinator.com/item?id=44723418
It is also highly compatible with the internet both in terms of technical/performance scalability and utility scalability (you can use it for just about any information verification need in any kind of application).
- Philpax 11mo agoUndisclosed self-promotion.
- Edmond 11mo agoMy motivation is less about self-promotion at this point and perhaps just frustration with the face-palm quality of the failure to properly implement information verification on the internet. Every time I hear about some dumb approach to age verification (conversation analysis...really?) or a romance scam story because of a fraudster somewhere in Malaysia..I have the need to scream...THERE IS A CORRECT SOLUTION.
- triceratops 11mo agoAge verification doesn't have to be perfect or even cryptographically secure. We don't demand it for alcohol or tobacco: carcinogenic, addictive substances that cause (in the case of alcohol) impaired judgment leading to deadly accidents. There's no justification for online age verification to be more invasive or stringent than what's done today for buying alcohol or tobacco IRL. My proposal is here: https://news.ycombinator.com/item?id=45141744 https://news.ycombinator.com/item?id=45141744
- wanderingbit 11mo agoThere are a couple big problems with this type of digital and decentralized type of authentication (I say this as a long time cryptocurrency professional who wants this to succeed): 1. backups and account recovery: We’re working with humans here. They will lose their keys in great numbers, sometimes into the hands of malicious actors. How do users then recover their credentials in a quick and reliable manner? 2. Fragmentation: let’s be optimistic and say digital credentials for drivers licenses are given out by _only_ 50 entities (one per State). Assuming we don’t have a single federal format for them (read: politically infeasible national id) how does facebook, let alone some rando startup, handle parsing and authenticating all these different credential formats? Oh and they can change at any time, due to some rando political issue in the given state. OP, you clearly know all this, so I’m just reminding you as someone down in the identity trenches.
- Edmond 11mo ago1.Backup and recovery with this solution is no different from backup and recovery of your phone. It is a potential issue but not unique. Cryptographic certificates and associated keys reside on your device. 2.The data format issue is (or was) indeed a concern though it was never insurmountable. A data dictionary would have been the most straight forward approach to address it: https://cipheredtrust.com/doc/#data-processing https://cipheredtrust.com/doc/#data-processing I say data format discernment was a concern because as faith would have it, we now have the perfect tech to address that, LLMs. You can shove any data format into an LLM and it will spit out a transformation into what you are looking for without the need to know the source format. Browsers are integrating LLM features as APIs so this type of use would be feasible both for front and back end tasks.