4 ms·
If the hammer ever comes down on this issue, ie hardcore requirement for age verification, there are ways to do this while protecting privacy. We are experimen
by Edmond 9mo ago
If the hammer ever comes down on this issue, ie hardcore requirement for age verification, there are ways to do this while protecting privacy.
We are experimenting with bootstraping a PKI certificate trust chain for facilitating trust projection and information verification online. Think of it as the ability to do things like age verification at scale via a peer-2-peer ish mechanism instead of sending your government id to a service provider.
One experiment is with PGP key holders (for now Keybase key holders) as CAs:
https://news.ycombinator.com/item?id=46576590 https://news.ycombinator.com/item?id=46576590
And also .gov email holders:
https://blog.certisfy.com/2025/12/using-gov-email-addresses- https://blog.certisfy.com/2025/12/using-gov-email-addresses-...
It's all self-service and requires no sign-up or download of anything, the app (https://certisfy.com/app https://certisfy.com/app) is an in-browser app and all the cryptography happens in the browser.
- mschuster91 9mo agoWhy so complex. ID cards could solve that issue, every European ID card has a powerful and programmable crypto processor / secure element inside and so do all ICAO compliant passports. Have the website emit a random nonce (to guide against replay attacks / reuse) plus an information what is requested (name, DOB, address, some like the Croatian ID card even store photographs), the card prepares a response with that data, signs that using its private key (with a 2FA being possible as well by using a PIN/password) and returns it to the website. The Croatian ID card doesn't even need a middleware because it doesn't do 2FA, you can ask it all of that by pure NFC communication. The German ID card requires a middleware ("AusweisApp", open source) for added protection though.
- Edmond 9mo agoAge verification could indeed be implemented in other ways. The approach outlined above is for information verification and trust projection in general, meaning you can put just about any verified information on a certificate and it can be used online. Here is a concrete example of how trustworthy certificates can be used online, this is my personal profile on bluesky with verification that is independent of the Blue sky service: https://bsky.app/profile/bitlooter.bsky.social https://bsky.app/profile/bitlooter.bsky.social If you click on the profile image you can enter that code into https://certisfy.com/app https://certisfy.com/app to verify the identity of the profile. That sticker could be on any online profile to prove high quality authenticity, it could for instance be on an e-commerce site to prove that the site isn't a scam.
- LukeShu 9mo agoIn 2005, we decided that we were going to have Real ID by 2008. We're now looking at a 2027 completion date.
- pyuser583 9mo agoAt the airport they said I wouldn't be able to travel unless I had a real ID by 2019.
- LukeShu 9mo agoFirst they said you wouldn't be able to travel unless you had a Real ID by 2008. Then they delayed it. Many times. Based on which airport/facility and what state your ID was from, some enforcement started in 2014. Not all states were even issuing Real IDs yet in 2019. Finally, in 2024, all states and territories are issuing Real IDs, but full enforcement won't be until 2027.
- ekr____ 9mo agoThe problem with this specific design is that it reveals your identity to the site, which is obviously undesirable from a privacy perspective. For those who are interested one of my recent newsletter posts goes into a fair amount of detail about the various technical options here for using digital IDs in this context: https://educatedguesswork.org/posts/age-verification-id/ https://educatedguesswork.org/posts/age-verification-id/
- wmf 9mo agoGoogle and Apple already have private age verification so I think the time for experiments is past.
- vorpalhex 9mo agoCan age assurance be done privately and anonymously? Absolutely. But the entire point of age laws is to stifle free speech and ruin privacy. Thus why every age law requires uploading an ID. If it was just age, just require a credit charge of a $1 through an intermediary. Good for a year or whatever.
- Nextgrid 9mo ago> the entire point of age laws is to stifle free speech and ruin privacy Does it? I mean sure, it's a side-effect that some (most?) politicians might find desirable, but there's also people who just want to restrict access to adult material (not taking a position on whether it's a good or bad thing here). Most parents would probably agree with the latter even if they don't with the former.
- vorpalhex 9mo agoIs there anyone who can't do this today? Adult websites self label, and both your router and ISP offer removing adult websites as an option. If your kid is going to get around that by clever vpn use, age gates don't help.
- Nextgrid 9mo ago> If your kid is going to get around that by clever vpn use, age gates don't help. I think politicians and their supporters believe they do help. Of course from their perspective the only way to know for sure is to implement the restrictions (regardless of whether they succeed, at least they fulfill their campaign promises to their electors of "doing something").
- michaelt 9mo agoI don't have any children myself, but as I understand it in the modern age: Your kid's smartphone can connect to home wifi, mobile data, public wifi, and friends' home wifi - so network filtering alone won't cut it. And 'Encrypted SNI', 'DNS over HTTPS' and Cloudflare makes network filtering much harder than it was 15 years ago. On top of that, there's loads of porn posted on Reddit, Twitter, Twitch and suchlike. So any effective block is going to have a lot of collateral damage.
- Nextgrid 9mo agoMy concern with this is how far it goes and whether it has unintended side-effects. There are a lot of situations in history where in retrospect being able to evade government oversight and restrictions turned out to be a good thing. During the Holocaust a number of Jews and other targeted populations were able to escape hostile territory because they were able to get forged passports and other documents, something that strong cryptography would make impossible (even in a perfectly privacy-preserving way). I'm not sure how old you are or when you started in tech, but in my case I started as a kid and was able to build the skills that now gave me my career thanks to unrestricted Internet access (and sure, I saw pornography a few years earlier than I should have - didn't seem to have any measurable detrimental effect on me, especially not compared to the cigarettes and alcohol). This wouldn't have been possible if age verification was properly implemented, since a lot of the resources that might be useful for someone to learn programming/sysadmin could also be used to circumvent age verification and thus would've been blocked, and I would probably be working a minimum wage job and/or engaging in crime to sustain myself as a result. If I had to choose whatever harmful effects from pornography versus having a min-wage job, I'll take the porn side-effects any day, at least I have a roof over my head.
- rockskon 9mo agoI find claims of any technology being able to simultaneously validate your age while "respecting privacy" to be suspect at best. Even if the technology could work in theory, it would be built on top of an ecosystem designed around an ecosystem hell-bent on monetizing info about you.
- jazzyjackson 9mo agoZero knowledge proofs can perform expressions that check values within a JSON tree without exposing any of those values to the requesting party, for instance "year of birth < 2005" can return true or false without returning the person's numeric birth year. Essentially the requesting party has the holder of the credential perform a computation, the result is guaranteed to be the result of each and every instruction over a target data structure (only knowing the hash and signature chain of the credential, so for instance your government issued id can be signed by your secretary of states public key) Estonia has a really interesting government issued public key infrastructure where users can validate their identity with their physical ID card and a USB reader (maybe it's NFC by now?) but I don't think I've heard of the above scheme used in practice, just sat through a presentation at the internet identity workshop.
- rockskon 9mo agoZero knowledge proofs based on too little information are trivial to abuse. To combat this, you need to have it based off of more and more personal info....which is at odds with the privacy-preservation goal. Sadly when it comes to age assurance, Zero knowledge proofs are little better than marketing.
- deleted 9mo ago[deleted]
- ekr____ 9mo agoIn this case the ZKPs are tied to a private key stored in a secure element in the phone, so effectively they are tied to control of the device where the original credential was enrolled.
- pyuser583 9mo agoI read, from a semi-reliable source, Lousiana has pretty good system for verifying age and protecting ID. But's focused on in-person ID for gambling. The system was that they hired a company to make the cards, and assume civil liability for any privacy violations. They also required to the company to hold insurance in case of a claim. So it fell to the insurance company to sign off on the standards, and allowed investors to make money by avoiding claims. I might be half-remembering it but that seemed like a very good system.