"The Internet sucks. Get offline," is the battle cry of someone who likes Marvel movies and the book that Target has at the checkout line, or lives in one of about five cities in the USA.
Sincerely, your fellow terminally online HN commenter.
The joke about middle-of-nowhere towns is that the only thing for teens to do in meatspace is to go to the Walmart. Because there's nothing else to do.
I'm not joking: I'll bet that NO ONE at your local library cares that you're weird so long as you're polite and follow the rules.
I boulder, run, play tennis. I read about thirty books a year. I have lots of hobbies. But the Internet has made them better. I write novels. The people who help me with beta reading are online, because no one IRL is interested in what I write.
Again, expanding one's social circle.
As I said, this is something people who live in about five cities think. Congratulations on living in one of them for your entire life.
Most of us had to do something like look in the yellow pages for a martial arts school, discover there were none, and be sad. Hell, I live in one of the ten most populous cities in the USA, and there is literally zero chance to play squash because there are no facilities in the entire city.
I couldn't watch anime beyond Sailor Moon until I was 17 and went off to a summer camp at a university in a big city. My roommate happened to have loads of knowledge and a big collection, which he graciously shared with me. He'd, of course, acquired it all with the Internet. Something unavailable to me.
Now extrapolate for hobbies that don't require a physical space, where you can find others on the Internet, even if everyone in a hundred mile radius of you thinks that hobbit is for "queers."
That's a tall order, although there are plenty of reports of younger people switching to "dumb phones." I've switched to one myself. But how could you possibly stop it? They are terrible -- now that I don't have one anymore it's insane how many people are constantly staring at their phones, walking on the sidewalk, crossing the street, etc. It's really depressing.
But ya, at this point I don't care if parts of the internet are fine and if I had the power to burn it all down, I would.
To my understanding then, the issue is that the EU's implementation only has a ZK-based solution in the plans so far.
But then this initiative says "No Digital ID", not "No Auto-Deanonymizable Digital ID", so...
Yes it does, because zero-knowledge schemes take it as an assumption that all of the people who are supposed to have credentials can be trusted not to share them with people who aren't, since you're proposing a system that provides no means for that to be detected. And this context doesn't allow that assumption.
With a normal ID, the entity required to demand ID compares the picture on the ID to the person using it, which obviously doesn't work when they're not being provided with any identifying information. You thereby have no way to know that the ID belongs to the user and anyone can allow anyone else to use their ID, thereby defeating the system.
Which means that the proponents would never be satisfied with the result and the only thing building that system does is entrench something with the shape of a non-consensual identification system, which will then have any ZK features disabled (assuming they were actually implemented to begin with) when the consequences prove unsatisfactory.
No, ZK schemes have absolutely nothing to do with sybil resistance. That's a threat modeling concern anyways.
If your point is that the entire digital ID plan is nascent because it remains vulnerable to sybil attacks, that it may very well be, and so indeed there would need to be extra-technological measures to ensure the 1:1 mapping. That is no longer a cryptographic or technological concern however, but a governance and incentivization one.
It also means that it can't "kill the internet" then though, doesn't it?
> which obviously doesn't work when they're not being provided with any identifying information. You thereby have no way to know that the ID belongs to the user and anyone can allow anyone else to use their ID, thereby defeating the system
This is about digital identification. The facts you list off are beyond the analog hole. What you describe is (or at least should be) a non-goal for any scheme in this context, because it is fundamentally unsolveable.
> Which means that the proponents would never be satisfied with the result and the only thing building that system does is entrench something with the shape of a non-consensual identification system
This is (loaded) political speculation, not an argument.
Any effective form of sybil resistance itself compromises the privacy that ZK proofs allegedly provide.
Example: You create an account which is then unintentionally linked to your identity in some way, or someone doxxes you. That account is now irrevocably compromised and you need to create a new one, but any effective anti-sybil mechanism prevents you from doing so.
Example: Services use "sign in with Google" or similar to link your activity across services. To prevent this you need a separate Google account for each service, the exact thing any effective anti-sybil mechanism would prevent.
Example: A journalist is doing a series on some company's shady practices. After the first installment, the company uses the published description of the account activity required in order to write the story to identify the small subset of accounts that could belong to the journalist and then bans them or makes their accounts behave differently than ordinary accounts to prevent them from investigating further. An anti-sybil mechanism prevents the journalist from creating a new account not in the identified subset.
Example: A new company wants to create a search engine. Shady websites want to present different content to the search index than they do to users who visit. To detect this the company needs its systems to sometimes request content in a way the site can't distinguish from an ordinary user, to make sure it matches what will go on the search results page. Provide the scammers with an anti-sybil mechanism and once they identify which clients are validating their responses, they give the identified clients the same responses as they give the indexing bot, the search engine can't create new unidentified clients (even while attackers can via identity theft) and you get more scams in the search results page.
Example: A researcher is trying to determine if a service is using redlining, i.e. discriminating on the basis of location. To do this they need to create separate uncorrelated accounts that differ only in their address. An anti-sybil mechanism prevents this.
Example: There is a service the use of which intrinsically reveals some data point about you, e.g. narrows you down from one in 8 billion to one in a billion, each time you use it. Use it twice and it's one in 125 million, then one in 16 million and so on. If your current use isn't correlated with your past use then this is fine. If it is, which is the thing anti-sybil measures require, then repeated use of the service forces you to become uniquely identified.
That's the motte and bailey of zero-knowledge proofs. You present something that would protect privacy as long as it isn't combined with something else that would compromise it, but when it is then the proposed system doesn't actually protect privacy, and if it isn't then it serves no access restricting function and makes the system ineffective and pointless.
> What you describe is (or at least should be) a non-goal for any scheme in this context, because it is fundamentally unsolveable.
That's the point. Identifying someone without identifying them is fundamentally unsolvable. Zero-knowledge proofs cannot make the impossible happen, there is no cryptography that can give you that. But that is the claimed goal of the system -- to prove that someone has characteristic X without having any other information about them.
When you have no other information about them, you cannot establish that they are the person with characteristic X. Anyone can let anyone else use their ID. When you do, the use of zero-knowledge proofs does nothing to prevent the use of that other information to identify them.
> This is (loaded) political speculation, not an argument.
Reasonable political predictions are a valid form of argument. Authoritarians using mass surveillance for oppression and worse has an enormous amount of precedent and the consequences are orders of magnitude more severe than any possible advantages of any form of digital ID.
Before you further grant me any other imagined positions and misunderstandings, I actually do not happen to think that digital IDs, as currently conceived or with ZK, are better than pussy either. I just don't find them immediately objectionable. This is possible through the magic of not having a settled position on them just yet, as it's clear I have stuff to catch up on, as I'm not from the anglosphere (and thus Orwell's works are not culturally indoctrinated into me), and as my two options to learn more are:
- word salads published by various impossible to follow EU bodies
- people who think having an ID alone is like, literally 1984, let alone a digital one, and will "discuss" the subject accordingly
Somehow, this keeps me at more than an arm's distance away.
It's also generally unconvincing to keep reading about how xyz is not possible, from the people who would very blatantly object xyz even if it was entirely possible.