I don't think it's Godwin's Law when you are so spot on, exactly describing the worst case.
I don't think it's Godwin's Law when you are so spot on, exactly describing the worst case.
However even if the app is secure the storage and handling of the information is a different matter and it has been shown that care is not always taken.
To avoid rounding up the jews you... create a government that doesn't round up jews.
You don't fight arbitraty useful tools which then end up in bizarre situations like in US where people can't vote because of this bizarre idea that government shouldn't track voter lists.
EU governments mostly have a list of registered citizens with their birth dates and their adresses. And noone has been rounding up anyone for almost a century... something we can't say for another world country which apparently doesn't keep records of their voters (useful to prevent people of colors from voting!) and somehow is rounding up people on the streets right now.
But I have to point out that NL gov did not round up jews, but the bad outcome arrived anyway, from outside the system. So in the example we're talking about, that was not a solution.
Other than that, I agree.
https://www-bitsoffreedom-nl.translate.goog/2026/07/06/aivd-...
Amusingly fantastically wrong.
NL may have its own issues like you linked to, but more uniquely had their collected data abused more than other countries in probably the worst event in history.
How is, of all things, an age verification app going to make that worse?
I mean I understand your argument in principle but it seems you’re arguing against ~every present-day functional government and not against an age verification app.
Like if I was the boss of a train company I would probably not put up a photo of Mussolini as a motivational poster. Well… maybe I would, but only ironically.
> How is, of all things, an age verification app going to make that worse?
What are you arguing for, here? If everything were perfectly anonymous, maybe. But NOT ONCE in history has governments decided to not abuse power. It'd be so easy to just put a tracker in there or something.
All these "think of the children" arguments are ALWAYS red herrings. Literally any action, any freedom denied, can be justified in the fight against CSAM. And so they get rushed through and abused.
The EU DNS filter (CSAADF) was literally IMMEDIATELY abused to block other things too.
"It's just age verification". Is it, though? How do you verify age without verifying identity? How do you verify its use, without tracking. Provably without tracking. Provably without what's called "turnkey tyranny"?
I think if your argument, which is an extremely common argument, is "I just want to block children's access to bad stuff on the Internet", then you cannot possibly have been paying attention to this debate that's been going on since at least the mid 1990s. Were you even born when this was being discussed? If that's your argument then you have about 30 years of catching up to do before you should speak.
[1] yes, I know Mussolini did not in fact make the trains run on time.
zero-knowledge proofs
the point is non-govt entities shouldn't get any information about you during age verification other than that you're over 18 and that's what ZKP can give you
I'm sorry, you can't just drop "quantum computer", or "zero knowledge proof", or "flux capacitor", and think that you have solved the problem.
Just dropping "zero-knowledge proof" as if it's a mic drop moment is like when Turnbull said "the laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia".
The devil in all this is in the details. Just saying "zero-knowledge proof" is just barely more productive than saying "won't someone please think of the children?".
If you don't have a complete solution, then you're "not even wrong".
In addition to that, you have misunderstood how zero-knowledge even addresses the main problems. Not the technical problems, and DEFINITELY not the meatspace problems.
Second: There was some substance. Maybe not six paragraphs worth, but there was some. Here it is: You, when you said "zero-knowledge proofs", did not give much substance. How, specifically, is that going to work?
It's a bit rich for you to be complaining that knorker didn't have any substance, when the problem is that you didn't give any.
I felt your comment was so uninsightfully vapid and arrogant that it's uselessness could not be described briefly.
But sure, it does boil down to "sigh, that's not even wrong", but I suspect you not only don't know what that means, but that you would not be curious enough about life to look it up.
I note that you still did not provide a solution. You didn't even describe the requirements, and the problem here starts with a problem definition that doesn't inherently lead to it being either logically unsolvable, or leading to turnkey tyranny.
Edit: I use punctuation because I was born in the 1900s. And was on the internet when this issue started in the 90s, which makes me react to your "why don't we just...".
And if you look carefully, you'll find my punctuation choices are clearly un-LLM-like.
Governments likely already know your name, age, place of birth, so having an app with a standard API for verifying users isn't giving the government additional data.
so it will gather extra data, sell it sideways and leak like hell. (as they already do with all the data they already have)
https://digital-strategy.ec.europa.eu/en/factpages/blueprint...
First, the user downloads the app onto their phone and sets it up by certifying their age. This can be done with a biometric passport/ID card, a national eID (e.g. national ID Card or other electronic identification mean), a pre-installed third-party app (e.g. a banking app), or in person (e.g. at the post office). Only the information confirming that the user is over the age will be saved in the app. No name, no birthday, or any other data is saved.
After completing this step, the communication between the app and the provider certifying the user’s age (e.g. eID, third-party app) ends. No further data is exchanged.
https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verific...
For me, it's enough that your activity could be linked to any unique identity. I don't want mandatory government apps on my phone, that's very chinese. We should strive for better.
Edited to add: your linked FAQ conveniently leaves open how the communication between the web site and the app happens. There are myriad of ways that ones behaviour leaks in this step.