6 ms·
Privacy-preserving age and identity verification via anonymous credentials
- tatersolid 7mo agoTitle has been modified by this submission. Actual title of article is Anonymous credentials: an illustrated primer.
- FrasiertheLion 7mo agoMost people outside of a narrow set of cryptography engineers are unfamiliar with the term anonymous credentials, while age and identity verification are two privacy-invasive requirements that are being heavily discussed and rapidly being written into laws lately. The post's intro discusses both quite heavily, and they form the author's entire motivation for writing the post. The central question the post attempts to answer is "The problem for today is: how do we live in a world with routine age-verification and human identification, without completely abandoning our privacy?" My rephrase is an attempt to surface that, compared to the dry and academic title that will get overlooked. I think this is a very important topic these days where we are rapidly ceding are privacy to at best, confused and at worst, malicious regulations.
- TekMol 7mo agoI only skimmed the article, but the proposed solution seems to be that the authority (the "issuer") sends data to a device the user owns but has no control over. Like an Android or iOS phone. The data is of such form that the phone then can pass challenges of type "are you of at least x years old" without giving out any other information. And the user cannot share that data with other users because their phone will not let them.
- rapnie 7mo agoNote that there is a broken link to "great paper" in: > These techniques are described in a great paper whose title I’ve stolen for this section.
- sxzygz 7mo agoI believe they were attempting to link to https://eprint.iacr.org/2006/454 https://eprint.iacr.org/2006/454 a paper titled How to Win the Clone Wars: Efficient Periodic n-Times Anonymous Authentication.
- screwt 7mo agoThis article is a great explainer of the basics underlying anonymous credentials. I look forward to the promised follow-up explaining real-world examples. The key issue however is trust. The underlying protocols may support zero-knowledge proofs. But as a user I'm unlikely to be able to inspect those underlying protocols. I need to be able to see exactly what information I'm allowing the Issuer to see. Otherwise a "correct" anonymous scheme is indistinguishable from a "bad" scheme whereby the Issue sees both my full ID and details of the Resource I wish to access. Assuming a small set of centralized Issuers, they are in a position of great power if they can see exactly who is trying to access exactly what at all times. That's the question of trust - trust in the Issuer and in the implementation, not the underlying math.
- lwkl 7mo agoIn Switzerland a digital identity like this will launch this summer and the underlying infrastructure and app is open source. And the issuer of the ID and the registry that holds and verifies credentials are separated. The protocol also isn't novel and is already used in other countries (Germany(?)). For more information check the out technology behind it: https://www.eid.admin.ch/en/technology https://www.eid.admin.ch/en/technology
- Normal_gaussian 7mo agoThis is exactly it. It is a huge issue if the authentication can trivially become non-privacy preserving in a way that is impenetrable to users.
- LorenPechtel 7mo agoAnd a huge incentive for the black hats to undermine the issuers. They aren't going to remain secure.
- imglorp 7mo agoWe all know these laws are about suppressing dissent and not about age. If anyone implemented this privacy preservation scheme, would all the laws flip to say "yeah we really did mean it govt id tied to your post".
- zug_zug 7mo agoAll the more reason for us to get out an actual implementation of age verification that IS anonymous first, so that when a law is pushed for or passed, companies can adopt the anonymous implementation.
- jaimex2 7mo agoNo, there's no compromise here. Anyone pushing for age verification or going along with it needs to get replaced by a service that is immune to government overreach.
- sanex 7mo agoSome of us do see value in age and identity verification if the anonymity problem is solved so I very much disagree.
- fwn 7mo agoMight be vulnerable to classic salami tactics, though. Once we arrive at a general consensus on new norms that expect age verification online, we can just legislate it to ID users as a step 2. Maybe wait for the next terror-attack before pushing for it, but it's an easy fix to a culture that already accepted a layer control against the user. The end user will only perceive a small difference in whether they provide full ID or just verified age information. I want to believe that some supporters of age verification are not cynical. However, whatever good can be achieved through age verification seems such a small win, compared to the dangerous precedent it sets for the internet in general. I cannot get my head around it.
- LorenPechtel 7mo ago
- lachiflippi 7mo agoI've been really enjoying all these articles proposing solutions to anonymous age verification, mainly because most of them are written as if this has never been implemented in the real world. German IDs support age verification that just returns a yes/no response to the question "is this user above the age of 18," and not a single service in the entire country supports it. Anonymous age verification isn't a technical problem to be solved, as it's already been solved, it's a societal problem in that either the companies or the politicians pushing for age verification don't want to support it.
- 2Gkashmiri 7mo agoI remember reading in tech magazines about the "foss" acheivement which went on to become Aadhar. Remember this was prior to 2007 I think. The idea was your id would be an autehnticator of sorts. You need to verify yourself, the website asks Aadhar if the person is genuine, the website returns binary yes no. Same for you, is gender male? Or ages above 18? They would not return any other data. In the end, it became just another "formality" and tool for politicians and to flex muscles. People ended up taking photocopies of your card "just in case" and "that's the norm" even when it was said that's a bad idea. People still do Aadhar kyc but it is in hands of politicians now and the bureaucracy.
- matthewdgreen 7mo agoThe problem with these "yes/no" systems is that they also involve the websites you visit calling up a centralized party and asking if you're old enough. This is fine if the websites aren't interested (or if you really trust your government with your web browsing history), but gets unfortunate if you don't want to share that information.
- nijave 7mo agoI wish all governments would just run identity services and mandate usages that return anonymous attestations. Age being the most obvious attestation but something like residence status could also be useful. Something as simple as a JWT with claims (and random uuid id) would work
- noahdeesys 7mo agoThis implements California's AB 1043, which is the most promising for protecting privacy. Assuming it's not the start of a slippery slope. https://codeberg.org/noahdeesys/agegroupd https://codeberg.org/noahdeesys/agegroupd
- chocmake 7mo agoThere's a good explainer and Q&A of BBS+[1], which is one such zero-knowledge anonymous credentials standard, in a joint talk by cryptographer Brent Zundel. It covers the history of getting it into the W3C verified crentials spec and how various competing verified credential standards aren't privacy-preserving or as performant. It seems very promising and has considered various pitfalls. From what I understand the issuer signs a credential and then the user on their local device generates unique proofs based on the signature each time, preventing verifiers from colluding/tracking the original signature across services. It also seems to be designed with safeguards against the issuer. Info based on credentials can be selectively disclosed like whether you're over 18 or whether you have above a certain threshold in an account without disclosing the underlying data. Obviously if the type of services you use need literal PII then they can still tie activity to a real-world identity but for services only requiring age assurance being able to prove you're over 18 without providing the actual age or other identifiers is better than solutions being actively used. [1] https://www.youtube.com/watch?v=dXlRIrrb9f4 https://www.youtube.com/watch?v=dXlRIrrb9f4
- txrx0000 7mo agoIf the goal was to protect the children, there are much simpler solutions. But for whatever reason, companies and governments are avoiding the simple solutions like the plague. Let me explain the simple solutions: Don't let phone manufacturers lock the bootloader on phones. Let the device owner lock it themselves with a password if they want to. Someone will make a kid-friendly OS if there is market demand and tech-savvy parents can install that and lock the bootloader. What about the non-tech-savvy parents? Don't restrict people from sideloading apps. Let the user set a password-based app installation lock if they want to. It should be a toggle in the phone's settings. Someone will make kid-friendly apps if there is demand. This lets average parents control what apps get installed or uninstalled on their kid's phone. But what about apps or online services that adults also use? Apps and online services can add a password-protected toggle in their user account settings that enables child mode. Let the user set the password and toggle it themselves. Parents can take their child's phone and toggle this. ---- Notice how easy these things are to implement? All of these features could be implemented in less than a week. But instead of doing this, they want to implement much more complicated schemes where the gov and corps control all the toggles, and you control none. Why is it like that? Surely there are no ulterior motives, right?
- b112 7mo agoWhere's the profit. One must be a realist. If there is no profit motive, it won't happen. Ever. One profit motive is "the government has regulations, I will be fined if I don't do this". Another is "my competitors do it, and people buy their stuff because of it". All the technical solutions are easy. And you're right, it's not about age verification, it's about profits. The same way cars are regulated to have air bags, couches be made from non flammable materials, and so on. Human nature has been the same forever. It will never, ever change. Ever. Profit drives all.
- txrx0000 7mo agoProfit does not drive all. There are other valuable things besides money. A healthy society must regulate shortsighted profit-seeking and power-seeking. That's what these conversations are for.
- cmxch 7mo agoHow about the better option- don’t.
- ReptileMan 7mo agoCan anything from this scheme prevent the issuer from figuring out that I have verified my age to a site? If the answer is no, it is once again a non starter. Both the government and the site shouldn't know who the age verified person is and both shouldn't be able to deanonymize them even if they collude.
- gnarlouse 7mo agoI have a really great, really novel solution that nobody has suggested before: Just ban social media outright. Facebook, Twitter, Instagram, TikTok, dating apps, etc. They created this problem. They're destroying the fabric of our society. Sometimes the best solution is subtractive.
- Hizonner 7mo agoThis is a really frustrating topic, because there are so many layers of wrong. First you have people running around claiming that systems are "anonymous" and "privacy preserving"... meaning that they're anonymous if you trust somebody you shouldn't be trusting. Just simple snake oil. Often offered by people who know perfectly well what they're doing, too. Then somebody like Matt Green writes something like this, or some standards committee decides to try to do zero knowledge right, or whatever. But (a) people don't understand how it's different from the snake oil, and (b) almost nobody understands how hard it is to get it right. Information wants to be free, and even if you have a perfect privacy-preserving protocol, it doesn't work if you embed it in a workflow that turns around and leaks the information you're trying to hide. So there are an infinite number of more mistakes to argue against. But all of THAT just distracts from the fact that age verification is a bad goal. Setting up an ubiquitous, actually functional age verification tool is just handing weapons to people like, say, [Ken Paxton, Attorney General of the great state of Texas](https://thehill.com/policy/healthcare/5762893-paxton-opinion-transgender-transition/ https://thehill.com/policy/healthcare/5762893-paxton-opinion...). A system like that is an attractive nuisance that should not exist. What people like that will do with it is far worse than any problem it could possibly solve. ... and that fact gets lost in all the other stuff...
- _slih 7mo agoshutting down the cameras rather than releasing the data tells you everything about what was being collected. the system was designed around the assumption that nobody outside law enforcement would ever see the footage.
- krunck 7mo agoIf issuer knows the identity of the user and the signature that it sent to her, and if the user passes on the signature to the resource, what's to keep the issuer and resource from conspiring and sharing information to track the behavior of the user? One has to assume that the signature is going to be just as unique as the serial number the user generated. see this image from the article: https://blog.cryptographyengineering.com/wp-content/uploads/2026/02/image-17.png https://blog.cryptographyengineering.com/wp-content/uploads/...