When I go to the grocery shop and I buy alcohol then I have to wait at the self checkout till until a member of staff comes to verify my age before I can pay for my shopping basket. That involves me showing them an ID (e.g. my driving license) and them having to verify my biometric (face) by looking at me and then looking at my driving license. This is time consuming and requires additional staff at self checkout tills, making them less "self checkouty".
On the other hand (or palm should I say :P) I could age verify myself only once at an Amazon One kiosk and then have my legal age linked to my verified palm. Now I can go and buy alcohol and when I present my palm then the checkout till knows that it's me (because unlike a driving license or credit card or phone I can't hand my palm to someone else). It knows that I'm of legal age to buy alcohol and therefore was able to do three things in one go: age verify, pay and reward points all via a single hand gesture. That is a win for the consumer and the shop as they don't need that extra staff anymore and there's less of a human bottle neck, leading to faster checkouts.
Why not do the same thing, but instead of verifying your palm you verify a device that's responsible for authenticating you? This could be a special phone app (like Singapore's SingPass[1]) or even a small card with a built-in fingerprint reader. Once you authenticate yourself to the device, it can attest to your identity and the transaction can be finished via NFC.
Seems like the best of both worlds - automate identity validation without a centralized biometric database.
Because my (imaginary) 12 year old son can grab my phone and then pretend to be an adult when doing booze shopping. This is the reason why most Western countries don't allow this kind of technology for age verification. For example in the UK you have to file an application if your new technology can be authorised to be used for age verification in pubs, restaurants and other venues and that wouldn't pass their requirements.
On the other hand, a palm cannot be given to a 12 year old person. If Amazon One uses an element of palm veins in their biometric template, then even if you chopped off your hand it wouldn't work anymore because the blood flow would stop and therefore fail the identification.
It is true that an adult could still pay for booze for a 12 year old by presenting their palm, but that is already the case today where parents can go shopping with their children and buy alcohol as part of the family basket.
EDIT:
At the end of the day, a biometric will ensure that the adult is actually physically present at the time of purchase, which is what the law requires for things like alcohol shopping. Devices don't have that extra layer of quality assurance.
EDIT 2:
> But why couldn't the device handle your biometric authentication? Your 12-year-old son can't (hopefully) steal your face or your fingerprint
Because what happens on the device is unknown to the thing which needs to know that you are of legal age. At the end of the day it's just a phone which says "yes person is above 18" but how do you know that my phone didn't just reply that because it was programmed by me to do so? If the biometric is verified by the Amazon One device which is not my personal device then it's infinitely less likely to have bene tampered with.
Presumably if a manufacturer made a device that didn't actually bother checking the fingerprint, the systems that integrate with these devices would have to refuse to accept claims from it.
1. https://security.stackexchange.com/questions/101862/what-adv...
Works just fine.
If my age verification was tied to my palm, I'd have to cut off my hand to let a teenager buy booze with it.
But I still don't feel this is a compelling argument.
However, one advantage of something external to your body is that if it ever does get compromised it is a lot easier to deprecate that thing and replace it with a new one.