4 ms·
Concrete ZKP age verification schemes are hardly zero knowledge. Imagine your idealized ZK address verification scheme. It would go something like: I show up a
by nullc 29d ago
Concrete ZKP age verification schemes are hardly zero knowledge.
Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.
Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.
To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.
Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.
Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.
- croes 29d agoadd MFA to the check
- deltoidmaximus 29d agoTo where, the site requesting the verification? Now it is no longer zero knowledge.
- croes 29d agoNo, to the ID to prevent abuse if the card get stolen.
- Spivak 29d agoWhich means the issuer has to be involved in every attestation and you aren't allowed to own/control your private key. The government shouldn't know if/how many times I use my ID—you would be essentially building a country-wide blackmail database since it's a near direct proxy for porn usage. And it doesn't even matter if it's true, people will assume it anyway. Your system effectively collects exactly the data ZKP is intended to protect. Which is a long way of saying "ZKP" isn't an answer to this problem because you can't actually have zero knowledge in a system where people have little incentive to keep their key a secret.
- croes 28d agoNope, your ID could work like a YubiKey with a fingerprint reader or you could add a OTP. No third part would know how often you use your ID. Why do people make up problems that are already solved? OTP and biometrics aren’t new security features and people don’t assume the government gets informed every time they use it.
- nullc 28d agoMy example is still just as good if the ID holder is complicit. But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.
- Spivak 14d agoAlso if you enforce the use of Yubikey or a similar DRM protected device then we're back to the user not actually being able to own/control their key. And if you don't it's a second password which can be shared out. "Just use existing OTP" is a model that assumes that people actually want to protect their credentials. This is a Netflix password sharing situation and OTP didn't solve it.
- pessimizer 29d agoadd a different ID check to the MFA if that doesn't work, then add more MFA to that new ID check. Eventually it has to work, right? It's definitely worth doing infinite security in order to avoid regulating social network algorithms, because
- croes 29d agoTo prevent abuse add MFA to the ID. Problem if stolen cards solved and still zero knowledge.
- croes 29d agoBTW your example didn’t compromise zero knowledge, only after you added further requirements the zero knowledge was gone.