5 ms·
I wonder if not private age verification could not be solved with the right cryptographic protocol. You would have to register using a digital ID with a govern
by Findecanor 6mo ago
I wonder if not private age verification could not be solved with the right cryptographic protocol.
You would have to register using a digital ID with a government agency, to get a age certificate. Most European countries already have digital IDs, used for all sorts of things: such as taxes, online banking etc.
Then that certificate could be used in some sort of challenge-response protocol with web sites to verify your age, creating a new user ID in each session but without divulging anything that identifies that particular certificate.
I'm afraid that the alternative would be that social media would instead require login with the digital ID directly.
- verisimi 6mo agoAlways with the increasing government control. Heaven forbid people go online without training wheels. We need safety nets everywhere - a grazed knee means the state failed.
- the_real_cher 6mo agoIn my opinion public private key is the base of all identification should be done. You keep your own private key and the government has your public key.
- rmnclmnt 6mo agoAgreed. But would mean having to educate people on security, privacy and computing in general… Pretty sure most government like having most people uneducated on such things
- the_real_cher 6mo agoI feel like you could do it in an app or a card with an NFC chip. People don't have to know security or cryptography to do their banking online. Either way it would be infinitely better than the current social security number situation we have.
- rmnclmnt 6mo agoAgreed. Not saying there are no ways to ease the process but someone has to put some effort
- kkfx 6mo agoOn which hw? Because a smart-card (if open hardware and FLOSS) might be safe, certainly not a smartphone.
- rurban 6mo agoThat's what I did with my Austrian goverment ID during the COVID times. Had to go the embassy to identify myself. Those times the Deutschland ticket was still cheap, so no problem.
- JimDabell 6mo agoThis is what Verifiable Credentials are for. https://walt.id/verifiable-credentials https://walt.id/verifiable-credentials
- kkfx 6mo agoAnd what exactly would be the purpose of age verification? Because defining someone "mature" based on their age is pretty hit-and-miss: we have plenty of adults, even of a certain age, who it's hard to imagine have ever finished adolescence, for instance. On paper, they are absolutely of age. We also had a certain Alexander the Great, emperor of a large part of the planet at 20. We had 13-year-old Pharaohs active in government. We also have gazillions of examples of apparently innocent rules being used to boil Chomsky's frog, one small temperature rise at a time. For the first time in a long while, I'm starting to sense a certain fanaticism on this topic here on HN, which sounds very much like the molecular agitation when water starts to boil.
- tzs 6mo ago> And what exactly would be the purpose of age verification? Because defining someone "mature" based on their age is pretty hit-and-miss: we have plenty of adults, even of a certain age, who it's hard to imagine have ever finished adolescence, for instance. On paper, they are absolutely of age. We also had a certain Alexander the Great, emperor of a large part of the planet at 20. We had 13-year-old Pharaohs active in government. That's really no different than age of consent laws. In the majority of US states (33+DC) that age of consent for sex is 16, 17 in 6 states, and 18 in 11 states. In Europe it is 14 in 14 countries, 15 in 12 countries, 16 in 20 countries, 17 in 2 countries, and 18 in 3 countries. All of those are somewhat arbitrary. There are many people over 18 who lack whatever maturity age of consent laws are trying to ensure people have before they can consent. Going the other way there are people who are under the age of consent in most of those countries or states who are mature enough that there would be no harm in letting them consent. Any particular population wide age of consent in a state or country then cannot simultaneously protect everyone who needs protection and avoid forcing protection on people who do not need it. It would in theory be possible to make the age of consent an individual thing where you have to be psychologically evaluated and if you pass you get your consent license. (A hybrid approach might also be possible--a high automatic age of consent like 21, with people under that able to apply for a lower age. Probably also combined with "Romeo and Juliet" laws so people under 21 who just want to fool around with people close to their own age can do so without having to be psychologically evaluated first). I expect that very very few people would be in favor of replacing the one size fits all approach to age of consent with such an individualized system.
- uniq7 6mo agoIn your proposed scheme, it is in the best interest of web sites to store the certificates from users indefinitely, since it's the only evidence they have that prove that their users are not minors. Since authorities have the power of accessing that data and identify the user who created the certificate, this scheme is not anonymous. Authorities can access that data via court orders today, or via a global automatic mandatory data sharing law in the future. In the example of USA, even if for some reason people still trust the current Government (although ICE already accessed private medical records to track and arrest people), I don't see why they should trust all future Governments which will have retroactive access to all that data.
- Epa095 6mo agoSo let's make it illegal to keep the tokens more than e.g 6 months. We should not underestimate the power of the legal system to enforce freedom and anonymity. And on the flip side, it's hard to create a technical system which can actually withstand the force of the government if it chooses to come after you. I believe the correct battlefield for freedom is the political one, in the end it decides everything. And neither guns nor technical tricks can secure freedom against a tyrannical state. Wuth that said, it does tickle the curiosity to think about! A technical-political solution could be to introduce a new actor, the broker. It sits between the webpage and the age-verifier, receiving the age-verification, but then giving it's own proofs to the webpage (so acting as a trusted middleman). Now to match up visitors with identities you need to get the data from both the webpage, the broker and the age-verifier. You could imagine that the broker were in a different jurisdiction, maybe even one without a close cooperation with the government. Maybe people could even choose their own brokers (among certified ones).
- uniq7 6mo agoSo let's trust all future Governments to never remove the 6-month law? Once the whole technical system is implemented, it will be trivial to remove that bureaucratic limitation, and somehow it will be sold as better protection for the children.
- deleted 6mo ago[deleted]
- sneak 6mo agoYou misunderstand. The child protection angle is just a cover story. The actual reason for this legislation is to ban anonymous publishing; to ensure that every post on the internet can be linked back to an identity for retaliation. Verified anonymous age credentials don’t allow for this, so they don’t matter. The negative privacy implications are the primary features of these laws, not a bug. It is intentional.
- O1111OOO 6mo ago> The child protection angle is just a cover story. The actual reason for this legislation is to ban anonymous publishing; to ensure that every post on the internet can be linked back to an identity for retaliation. > Verified anonymous age credentials don’t allow for this, so they don’t matter. > The negative privacy implications are the primary features of these laws, not a bug. It is intentional. This is it. Perfect. The amount of money pouring into surveillance of all kinds (led by companies like palantir and so many others). It's surveillance capitalism without the capitalism. People create these illusions about a system, about a country and will fight to the end to defend those illusions. The reality of what actually exists beneath the shiny (propagandized) surface is so much darker.
- Xelbair 6mo agoI hate this approach to them problem, because it is not a technical problem. Because it focuses on technical aspects and accepts the premise of 'age verification must be solved'. It doesn’t, and discretion what content and and what age children and teenagers can consume should be up to parents. Not government, nor corporations.
- chii 6mo ago"but we can't trust the parents to protect the children!"
- coffeefirst 6mo agoYou don’t need anything this elaborate. Set parental controls on set up, pass a single flag to websites and apps, similar to the Global Privacy Control. No privacy is lost. Control is handed to the device owner, and implementation is technically trivial.
- Epa095 6mo agoWould it not be trivial to make a webpage which proxies sites but with the headers removed, bypassing the whole thing?
- bryan_w 6mo agoCan't set local proxy because of parental controls, can't setup cloud proxy because of ... Being a kid.
- tzs 6mo agoThat's essentially the approach California is taking.
- mirpa 6mo agoAll you need is one authority which defines who can verify age threshold (government). Those who can verify age threshold need to know your age and identity (bank). Those who are bound to restrict access based on age only need to know in which country you live (website). Nothing else is needed eg. bank, identity and age is not known to the website, website is not known to your bank or government.
- anticrymactic 6mo agoWhile this would solve the technical problem at hand. It lacks any safeguard against a very simple workaround of sharing your certificate or even posting for everyone to use. Fullly anonymous + untraceable attestation --> unlimited certificate sharing
- ndsipa_pomu 6mo agoWe've already got age verification protocols (in the UK) with the sale of alcohol and tobacco. If we also use those shops to sell age verification tokens (e.g. something like a scratchcard) for a nominal amount, then people could reliably verify that they're an adult without the privacy concerns and without shoddy websites leaking credentials.
- akdev1l 6mo agoThen you can give the tokens to whoever you want that does happen with alcohol but it’s rare because well people don’t wanna go to jail for giving alcohol to a minor So your proposal would have to come with liability towards the individual
- ndsipa_pomu 6mo agoYes - pretty much the same as supplying tobacco/alcohol to minors. My point is that we've got a system which more or less works already, so it's just a matter of extending it for adult website verification.
- michaelt 6mo agoIt can't be solved, but you can choose different loopholes and privacy trade-offs. Untraceable-but-single-use proof-of-age tokens? Good for privacy, but now that 14-year-old can get tokens from an 18-year-old friend for cash. Proof tokens that only last a few minutes, or a three-way handshake between user, government and website? Harder to trade, but now the government's got a good guess about who's opening pornhub. Requiring sites to keep audit records, to prove they really did the verification procedure? Wildly insecure, we don't want them storing passport photos. Requiring them to not keep audit records? Then they can skip or half-ass the checks. Camera-based age estimation? Once again the 14-year-old can have an 18-year-old pass the check for them. Or a video game character creator or something. Scanning a government ID card? Better hope Dad never leaves his wallet unattended for 5 minutes. And not everyone has a passport or driver's license. Age attestation from an electronic driver's license, plus face id biometric validation, with a secure element, trusted execution environment and code attestation? Congrats, now you've handed your national ID database to the world's largest adtech/tracking company. Hope you weren't trying to distance your nation from US tech dominance.
- heavyset_go 6mo agoI've never seen the government try to make laws as damn bulletproof as this one "for our own good". You'd think we were dealing with access controls for nuclear waste here, but it's actually as banal as preventing a kid from just liking a photo his friend took using an app. It's insane seeing how this moral panic plays out.
- tzs 6mo agoYes, it can be. Google has a zero-knowledge proof based system in Google Wallet that lets you store store signed credentials such as government ID and then prove to third parties that you have such a signed ID and to disclose to them facts of your choosing from that ID, with the third party gaining no information other than that you have such an ID and that it confirms those facts. This has been running in production for a few months. They have opened source this [1][2]. This was designed to comply with eIDAS in Europe so that it could be incorporated into the EU Digital Identity wallet. Current implementations depends on smartphones but it should be possible to make it runs on other devices that have similar cryptographic hardware. [1] https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/ https://blog.google/innovation-and-ai/technology/safety-secu... [2] https://github.com/google/longfellow-zk https://github.com/google/longfellow-zk
- raxxorraxor 6mo agoMy government (probably illegally) saves connection information, so any scheme will fail regardless of implementation. Also, you probably just don't want any gatekeepers here and I think the net will just move to other services. I would also not want to use my "digital ID" for anything other than perhaps state services. I prefer to not give an inch as it is not in my interest, so trying to sell any solution is probably futile in my case.