4 ms·
I have mentioned this before, but age verification can be solved by hash chains. They can prove age without compromising privacy. It is crazy that the solution
by spragl 8mo ago
I have mentioned this before, but age verification can be solved by hash chains. They can prove age without compromising privacy.
It is crazy that the solutions Discord goes for are IDs and selfies. It definitely gives the impression that there are shady ulterior motives.
Hash chains are simple. If they were adopted, Discord would clearly be in bad faith taking the steps that they do now. If you search you will find quite a bit of information. My introduction to hash chains is for for age verification specifically:
https://spredehagl.com/2025-07-14/ https://spredehagl.com/2025-07-14/
- nicman23 8mo agothis is just a think of the children attack
- stingraycharles 8mo agoHow would that mechanism work in practice, though? If every parent needs to become a trusted authority, wouldn’t that just move the goalpost? Who would be the trusted authority, and who would implement that? I agree that the mechanism is elegant, but figuring out which entity should be trusted in a way that scales globally is somewhat difficult.
- IshKebab 8mo agoThe use of the parent is an example. In reality it would be some official age checking provider (maybe the government).
- spragl 8mo agoYes. I think that wahtever organization that issues your passport, would be a natural choice for setting this up. But nothing prevents it from being a private company, although I cannot see a sound business model for it. Also it would need to project great credibility for customers to trust them with their information.
- lrem 8mo agoRealistically this would be another service attached to the government ID. Something like this does function in some European countries, doesn’t it?
- xyzal 8mo agoIt works quite well in Czechia. Upon verification request, you are redirected to a government site, where you select exactly what data (Full name, DOB, address ... ) you intend to share with the entity requesting the information. I can imagine you could share just your DOB in such a case, while keeping your real identity private. In such a way Discord would learn only your age, keeping everything else from them. Government learns that Discord was provided your data, but this is supposedly a trusted, regulated entity.
- lrem 8mo agoA better system is in beta in Switzerland. Government is the root of trust, but only signs your private cert regarding your ID. All the interaction with third parties is local to your device, the government doesn’t get to know you interacted with Discord. Discord gets a single bit “is the user of this device 16/18 (restricted/full legal autonomy age) years old?” With chain of trust to the government.
- j16sdiz 8mo agoIt depends on you thread model and how much you trust government. In your model, government now know you are on discord -- they know where to ask when they want to find you. It really depends which government you are under.
- vasco 8mo agoIf the input is "give ID", what the software claims to do is almost meaningless since you cannot prove that software was running. What do I care that someone can tell me they built a privacy-first way of validating IDs/age if I cannot be sure that is the software they are running? They can just as easily save the ID to disk and return "all good" for all I know.
- spragl 8mo agoNo, the solution does not require that. It requires that Bob proves posession of a private key, that only he has ever had. That private key could be generated specifically for the commitment that he got from Alice.
- neuroelectron 8mo agoSomething like half of Israel's economy is intelligence gathering wtf do you think is happening here it's pretty obvious. economic leverage, surveillance, foreign influence, tech exports being used politically, etc.
- zelphirkalt 8mo agoEven easier, just get tokens that carry no other information from ones government, and the government runs an API, that for a given token tells whether that token is valid. Can tokens be stolen? Maybe. Can your face be stolen? Today yes.
- pbmonster 8mo agoWhat's stopping kids from all using the token of that one older brother?
- choo-t 8mo agoSame thing as using the ID or photo of the same older brother : Nothing.
- pbmonster 8mo agoNo, using another ID has a much higher barrier: more likely to get caught (it's the same ID, after all - tokens might (or should) be better anonymized so services don't build user profiles just using the age tokens), more likely to get punished (there's a real name attached to it), more likely to lead to a video verification request to compare ID picture with actual face.
- choo-t 8mo agoDiscord say they won't keep a copy of the ID, so getting caught for duplicate ID would contradict this narrative.
- zelphirkalt 8mo agoI don't see how this is worse than using a TAN list, or using someone's phone to circumvent 2FA.
- sebstefan 8mo agoNo API, they sign the tokens with the government's private key and you verify them with the government's public key If discord needs to contact an API, then the government can associate the token with you, and you with discord, and know what you browse online. No thank you.
- littlecranky67 8mo agoThe EU is working on a actual privacy-preserving initiative [0] that allows owners of ID wallets to verify their age, without their actual age or personal data being transmitted. The standard and reference implementations are open source on GitHub. Yet everybody screams uploading IDs and total government surveillance. [0]: https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/930450954/The+Age+Verification+Manual https://ec.europa.eu/digital-building-blocks/sites/spaces/EU...
- rdm_blackhole 8mo agoThe same EU that is trying to backdoor every messaging app to "protect the children" TM? I 'll use their ID system on my dead body.
- littlecranky67 8mo agoThis is just pointless whataboutism. There are smart devs and crypto experts designing a sound, privacy-friendly system that is open source. It does what is supposed to do and how everybody would want it to be implemented. Yet people reject it on irrational grounds for whatever negative aspect they associate the EU with.
- rdm_blackhole 8mo agoIt's funny how pointing a fact is called whataboutism. You trust the EU's pinky promise a keep their word that your ID will be safe and secure and never tied to what you say, the content of your messages or who you send them to. If that is so, then go ahead and use it. That's your business. > whatever negative aspect The EU literally wants to read your personal messages because it doesn't trust that you are not some criminal in disguise. Instead of the state having to prove that you are criminal breaking the law, it wants to read everything you send and store the data permanently in case you break the law one day. If you think that is acceptable and that is an entity that can be trusted, then I don't know what to tell you.
- 8mo ago
- pbmonster 8mo agoHow difficult would it be to add further anonymization? Let's say I want to prevent the bike shop from building a usage profile on the basis of the age check (e.g. because I'm buying booze). Would I just need to get more chains from Alice, or is there an easy way to integrate e.g. group signatures into the scheme?
- spragl 8mo agoI think the way to go would be for Alice to give you lots of commitments. They are computationally light-weight to generate anyway. That would at least be a good and also simple solution. Maybe there is a perfect solution, but then I dont know it.
- zaxioms 8mo agoIf you wanted to implement this in real life, who plays the role of Alice?
- spragl 8mo agoI think that whatever organization that issues your passport, would be a natural choice for setting this up. But it could be some other authority. In a way it is the identity owners and the providers that decide who they will trust as authorities.
- erfgh 8mo agoWell your solution includes handwritten signatures and everyone being a handwriting expert so that they compare handwritten signatures. I wouldn't call this an elegant solution.
- spragl 8mo agoThat is what the example uses. In the real world that would be a digital signature. Look under the heading "Fitting the parts together" to see what the real world solution could be like.
- mattstir 8mo agoI'm not sure how hash chains would resolve the fundamental issue of needing to send your ID or similar to some random third-party company that does god-knows-what with it (probably stores it in a publicly accessible path with big "steal me" signs pointing at it). That they need to attest to your age means that they need to trust what your age is, which has really just moved the problem one layer deeper (as far as I can tell).
- spragl 8mo agoI assume by third party you mean the authority, and yes, the authority would need to know your personal information. At least enough of it to verify your age. So the ideal is that the authority is the entity that already knows your personal information. Like the entity that issued your passport to you, or the one that issued you drivers license. But even if the authority was a private company, I think it would be an improvement compared to the current situation. In this situation your personal information would be held by this one company, and not whatever provider that needs to verify your age. Also, you would be able to use the commitments, that this private authority gave you, without any coordination afterwards. The authority would not know about your transactions.