- you enter ph and must age-verify. It says 'your secret: "capable peanut", enter age proof below'.
- you go to age-knower (e.g bank or government page). You provide the secret phrase, and you get back a cryptographically signed json with the secret phrase, a claim 'above18', and a field stating who attested for the age (e.g government or bank or whoever).
- you paste this signed json (maybe encoded as base64 or something) into ph. It will verify that the attestee is good, then use it's public key to verify the signature, before checking that the secret is the correct one, and that it contains the age-claim.
Is the problem that if ph and the attestee colludes they can compare the secret string and figure out who you are?