Site generates random key
Key and verification passed to verifier
Verified list is published
Site pulls list and checks its number has been verified
Site doesn’t know who it is, and verifier doesn’t know which site was verified against
Key and verification passed to verifier
Verified list is published
Site pulls list and checks its number has been verified
Site doesn’t know who it is, and verifier doesn’t know which site was verified against
If the verified list is tied against identity, there is only a simple law change required to de-anonymize everything.
Otherwise, why wouldn’t I just try the last entries from that list?
Now sure if the identity provider and the site work together they could negate the anonymity, but given that for the identity provider anonymisation would be the key selling feature they wouldn’t want to risk that. Mullvad I’m sure would be trustworthy enough.