Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This would not be anonymous and would allow website owners to uniquely identify the hardware used to authenticate.

So, once again: you can have a secure system XOR you can have anonimity.



Well it would be anonymous because the client public key is randomly generated every time, and the zk proof doesn't include the identifier.


If the public key signature of that random public key can't be uniquely identified as belonging to a particular device (allowing for a device to be revocated), then all it takes is 1 compromised phone to make the system insecure ...

(to say nothing of the fact that because of EU regulations the secure element is not app accessible on either apple or android. So you won't just be dependent on Google/Apple, you'll be using their APIs (which report every authentication to them) every single time an ID is needed)

If you can identify the device even just with a unique identifier, it's not anonymous.


I already described in detail how to do revocations despite the website not being able to identify the device.

The whole point of zero knowledge is that you can prove you have possession of information with particular properties, without having to actually reveal the information. I explained how to use this in my first reply to you. You're just repeating your claim without bothering to understand the first thing about the technology I'm talking about.

Age verification itself is a change to regulations. Obviously to make a private system, our regulations would have to change in a way that allows that, instead of in a way that destroys all privacy as they're attempting now.


And you again switch to dropping the other requirement. You would never be able to find the credentials to revoke to restore security if there is true anonymity.


The only requirement I dropped is absolute perfect security, which no system will have and certainly not the nonsense "show your ID to the camera" stuff they're actually using.

I showed how to eliminate proxies, and without that, the only hole is the credentials themselves getting passed around. If that happens at a small scale between people who know each other, it's a minor problem. If a credential gets posted online and widely shared, it's easy to notice and revoke it.


No you go in a circle. My claim is: the system can be secure XOR the system can be anonymous.

And you go in circles. One post, you drop anonymity, I point out that leads to security problem, next post you drop security and ... you get back anonymity, I point that out and, guess where we go from there? I mean your list of replies is becoming an ever stronger argument for what you're denying.


At this point I can only ask that you actually read my above comments more closely and think about them. I have exactly the level of security I described in my last comment, with complete anonymity, all with one design. If your claim is that this level of security is insufficient, my answer is that it's more secure than anything actually being used for age verification, by a significant margin.

The reason we keep switching back and forth is that every time you make objection A, and I explain how the system addresses that, you switch to objection B, ignoring that I already explained how the system addresses that as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: