This problem doesn't exist with today's simple prompts that just ask for your birthday and blindly trust the end user.
Surprisingly (to me at least), certain cryptographic tricks can do a pretty big chunk of that, by having the website/government and user/government interactions occur ahead of time. But as far as I can see, there's still the issue with these tricks that 18+ people could share their access with under-18 people, which the government would want to prevent.
Also, does appear Privacy Pass covers the other aspects, which is covered on this page, but still trying to work through if it covers all aspects of a system that at least for myself I would be agreeable to use for things like: age verification, citizenship, captchas, etc — basically anonymous verification of identity attributes.
I also don't really see how present physical identity could be proven in a privacy-preserving manner, if you don't trust the government or endpoints not to abuse that physical data. Alas, even if I take your word for it, I doubt that governments would implement such an indirect system for age verification in practice, especially since they might want to revoke any erroneously-issued tokens.
(And even if anonymous non-circumventable age gating were to become a reality, I still wouldn't be a fan of differential privacy regulations for minors, since many ordinary sites would become inaccessible to teenagers from following the path of least resistance. Either impose the regulations on all users, impose them gradually depending on age, or don't impose them at all.)
Wouldn't they know your IP address from which the request is coming? Or potentially use other browser tracking and fingerprinting tricks?
Maybe I misunderstood but it didn't sound like you were describing blind tokens issued in advance.
Thus, the government might learn that some user accessed that particular endpoint
In my view the government knowing the endpoint associated with an individual request is a critical shortcoming. It's just too short a crevasse for them to jump to get that missing piece (identity). Even if the protocol is sound there are other means (eg. force an endpoint to hand over logs, associate with authentications via timing or other characteristics, and use other tracking metadata provided by the endpoint itself or other third parties or even ISP's to figure out who accessed what). No thank you.
Also creates an easy, centralized chokepoint for more widespread censorship. Simply put, the government is not a choice actor I would trust with this type of capability. The technology is not mature enough to truly, in practice, provide the protections needed to do this right.
EDIT: This appears to cover some aspects, still reviewing it and to confirm it covers all the system attributes I described:
https://crypto.stackexchange.com/questions/96232/zkp-prove-t...
Obviously looking for example, but if you’re able to think of an additional issues that need to be accounted for, let me know.
Even then, if the government actively compelling endpoints to hand over their data is within the threat model, the government could inspect any cached temporary tokens to deanonymize the users. This could perhaps be mitigated with some way for users to irreversibly transform the temporary tokens given by the government, but I'm not sure if that's possible while retaining the ability for endpoints to verify the tokens.
Overall, though, the sharing problem seems to me to be the biggest issue by far with this scheme. What makes a user an individual human? In current implementations, their unique government ID (perhaps made illegal to falsify) is used for this. But I can't see how individual humans can be distinguished in a privacy-preserving way.
Never really gave system much thought at the time, since governments rarely want less data or to provide anonymous access — and average person does not care about anonymous access, in fact, in my experience they want everything logged. Same topic could easily be applied to numerous functions such as border crossings, but governments want to track who is crossing instead of just checking individual authorization to enter.
I first saw them used with Clouflare's Privacy Pass https://www.hcaptcha.com/privacy-pass, they've also been used with Google's trust token proposal.
For those interested, here’s the related paper covering it:
https://www.petsymposium.org/2018/files/papers/issue3/popets...
And yes, my understanding was tokens entered a pool of one-time tokens and neither the government or endpoint was able to cross reference them to a specific user.
Which to me might mean it might address if user is refused new tokens, it might not account for if the tokens are revoked or the authorizing entity ceased to exist, but the attribute was uniform, for example age.
https://privacypass.github.io/protocol/
All and all, at very least, appears to be an extensive and extendable standard, assuming those involved are reasonable and there’s no conflicting interests.
https://news.ycombinator.com/item?id=33133749
Ideally, endpoints would not even know the specific authentication provider, but that the authentication came from a authentication service that’s authorized to confirm a given identity and related attributes; for example, being over X age is a binary attribute and numerous entities should be able to authenticate that and it be honored by a jurisdiction similar to how passports are uniform.