Even if every state started putting contactless chips into drivers licenses to provide anonymous age attestation, you'd still have the problem a kid can just use a parent's or older sibling's card.
And even if such cards did exist and they were considered legally adequate, you've still got the problem that nothing except smartphones can read them. And you've got the problem browsers don't support them, and app stores don't welcome porn-viewing apps.
Of course, this is all intentional - the religious anti-pornography groups that push for these laws consider it a good thing that complying with the law is essentially impossible. They want a full ban on pornography, but that would get struck down as unconstitutional, so they have to get a ban by indirect means.
This comes up every time, but the purpose of the identity check is to ascertain (to the extent possible) that the person logging in is the person whose age you’re verifying.
If you completely separate identity from age checking using some cryptographic method, the loophole is that a single identity token with an adult age can now be used by everyone, everywhere to tell websites that they are above a certain age. So as soon as you did that, someone would just share (or steal) a token of valid age and post it online for everyone to use. Entire system subverted.
You could try to use a 3rd-party service that handles age check functions and implements some level of rate limiting to prevent this, but then you’re trusting that party to know about all of the porn websites and other places the person is trying to log in to. If that 3rd party is the government, well you’ve just created a convenient place for the government to collect stats about people logging in to porn websites.
There a two counter techniques used to address that problem. Tokens can get time limited down to a number of seconds (10-30?), and a single token is only valid for one session at a given website (assuming the website honor those restriction on their side).
In addition, token providers may rate limit how many tokens a person may generate, and the application that request tokens may require a bit of work from the user (like typing a pin). Any person who need to do more age verification could be required to contact customer support to unlock such features, which also mean the provider can keep a closer eye on accounts that generate tokens in strange or abnormal patterns. Depending on how the market for identity providers are, different providers may provide different service and different levels of authentication.
In Sweden currently we are in a situation where there are multiple competing identify providers. They have to follow a certain certification, but the exact details of the technology varies a lot. There is a bit of talk to make those an open standard, including defining exactly what information the provider and the recipient should get. There is also the hope that the user application could be made generic, so switching/choosing provider becomes easy.
The problem with the technology in term of privacy is not so much in the protocols or cryptographic methods, but rather a social one. You can not create an fair identification system if all it does is ID control for porn sites, just as one can not create a VPN if all it can access is porn sites.
So yes, you could steal the private key I guess. But that is no worse than if you have to prove your identity; someone could get your password to your account.
A zero-trust protocol or computer system is all well and good, for some uses at least. A zero-trust society will not work. Or at least it will be significantly worse than societies with trust.
zk proofs could be used to solve this problem.
- Govt runs a zk-prove-ident service
- User goes to PH and starts verification process
- PH does proof with Govt, this could be anonymous
Ideally the user's keys are part of their ID, if you lose your ID, you can get a new one. It's still a permissioned system, so no miners/stakers needed, we can make it possible to change/replace keys behind the scenes so the UX for the common people does not amount to "lose your keys, lose your money"
Suppose I want to start a business where I don’t want the liability of having to deal with all the laws about minors. Then I can use the government API to only allow people over whatever age.
That is not a reason for the government to not do something. We entrust them with nuclear weapons and aircraft carriers. Not to mention Snowden already proved the government has back doors into all the big tech companies, so it’s already not a secret who is visiting what website. And FISA courts and secret warrants under gag order and blah blah.
It’s just inconvenient for everyone.
For PornHub that also gives other companies, the OpenID providers, the power to censor PornHub but refusing to verify age or identity.
I don't really want GitHub knowing everything I sign into, but in some cases like Tailscale my only option is to tell GitHub about it or not use Tailscale.
It would still have many of the same flaws as OpenID, but at least you accessing a site wouldnt notify the authority.
Maybe " verifiable credentials" is the keyword I was missing. Thanks!
1. Introduce a X-PEGI HTTP header that sites can use to change the content. This would also be useful for other contexts such as cybercafes and whatnot.
2. Mandate that porn website abide by these headers.
3. Have responsible parents, lock their children's computers and add the appropriate header.
The adults then have access to the adult internet with no extra restrictions.
There's yer problem right there.
Apple is what it is today, might not be the same Apple tomorrow.
We need only look at... (checks notes) every other profit driven company (thats all of them) to see how this will go when quarterly earnings are flat and/or falling
It's literally impossible.
You can either have a zero knowledge system where the tokens are immediately compromised and widely shared that provides no authentication whatsoever, or you can have a system that has the ability to revoke compromised tokens that is not zero knowledge.
Or as we are likely to get, you can have a system that is both easily compromised and does not have zero knowledge, and the age verification industry is simply engaged in industrial scale lying to try and get themselves written into law...
As for it being centralised, I'm all for web-of-trust but I thought we'd pretty much given up on that?
I'm not aware of any large scale user implementations of the protocol though (people have been getting compatible ID cards for years, but I don't know any software that uses them outside of probably cigarette vending machines in Spain). Do you know any?
I don't know if that's what you're talking about but, in Belgium for example, to fill taxes online and to do various other types of pointless administratrivia you must use your EID card, which you put in an EID card reader (typically connected by USB).
Now the EU-wide biometrics, a sheer horror (the EU court of justice ruled that the biometrics data can be used for other uses and stored in databases outside the card... although at first it was supposed to be private), isn't implemented all around the EU yet.
My EID car was emitted in 2016 and is valid until 2026 and definitely doesn't have any biometrics data in it. I don't know if the system shall already be put in place in 2026 when I'll have to renew it for another ten years.
My point being: biometrics and NFC are probably not present on a lot of EU citizens' ID cards... Yet. So, atm, it probably doesn't make much economical sense to support that system for random usecases like selling cigarettes or alcohol.
Filing my taxes is the only thing I use my EID for.
Then there are some EU countries using their own "2FA" authentication system for anything "government related" (taxes, car registration, company filings, banks login, social security, etc.), complete with physical devices, phone apps, webapps, etc. which aren't using the EU EID at all. Basically: an entire ID system, using 2FA, but bypassing the EID entirely.
I'd say overall it's still pretty much the wild west.
The standard is ICAO 8303 for how the data structures work. It's the same as ePassports. EU cards implement EAC for the fingerprints, which has a whole mutual auth PKI system.
The problem will probably be adoption by services. It's a lot more tempting to get more information than just age, if you go through the hassle in the first place.
Wouldn’t it be nice if we knew we were interacting with a real person and not a chat bot?
Expanding on this… we should all be jealous of Estonia’s digital governmental infrastructure!