If the API asks for a users minimum age at a certain time, how can the government not know which data set it has to check?
If the API asks for a users minimum age at a certain time, how can the government not know which data set it has to check?
Some worthwhile reading on the topic if you're interested:
https://en.wikipedia.org/wiki/Zero-knowledge_proof#Zero-Know...
https://en.wikipedia.org/wiki/Blind_signature
It should even possible to construct a protocol where you can prove that you're over 18 without revealing your birthdate.
Zero-Knowledge Range Proofs: https://eprint.iacr.org/2024/430
"Zero-knowledge range proofs (ZKRPs) allow a prover to convince a verifier that a secret value lies in a given interval."
Umm, no. That is not how a scheme like this would work.
When implemented correctly, yes. I've edited my wording slightly to indicate that.
I just don't have faith in most countries, including Australia, to implement it with protecting the privacy of their residents in mind.
I disagree. I can't think of an implementation mistake that would allow just the government to see what services you sign up for.
You could of course screw it up so everybody could see. If the government put a keylogger on your device then they could see. However broadly speaking this is not something that can be screwed up in such a way that just the government would be able to see.
The protocol wouldn't even involve any communication with the government.
Not just theoretically posdible, people have done it: https://zkpassport.id/
"This is experimental software. While it has undergone external review, it has not yet received a formal security audit. Please use with caution and at your own risk in production environments."