HNHacker News
TopNewBestAskShowJobs

mikeysight

22 karma · joined August 11, 2026

https://loginwithone.com
submissionscomments
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

fun times

mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
the service doesn't see the document itself on subsequent verifications but it does receive a signed verification payload containing derived fields in plaintext currently. No ZK proofs at this stage but agreed it would be a great future improvement!
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
I wasn't familiar with this protocol, thank you for sharing. I have something similar to this in the works right now along the lines of passkey-bound session keys that can be used without the user being present.
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
the recovery flow is scoped to the account but not the encrypted data. if the passkey is lost, the encrypted identity data is lost (by design) and the user has to upload again before new verifications. the account and associations with previously linked applications remain.
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
Great question, and also thank you for calling this out, because "selfie data" shouldn't be included in that description, since those images are not persisted at all, encrypted or otherwise (editing now). You make a very good point about being able to reissue valid proofs based on a previous verification (and I think that could even be a viable user opt-in down the road) but the identity data that is persisted serves two main purposes: 1. reusability across applications that require a proof scoped to a valid government ID for legal purposes (non-expired, for example) or with a recency requirement (fresh photo matching the ID photo to validate you're the person holding the ID), and 2. as a means for users to self-custody their identity documents for presentation as needed across the web (future KYC ambitions for the project).
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
I wrote up more of the thinking behind this here for those interested:

https://loginwithone.com/blog/the-internet-should-be-more-li...

mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
> ONE still sees identity documents in the clear the first time when it verifies them, right? Otherwise we could upload fakes.

Yes that's correct, the identity documents are validated alongside the selfie before the selfie is discarded and the identity documents are encrypted by the passkey-derived encryption key prior to persistence.

> Also I'm not familiar with Oauth 2.0, but doesn't ONE know the client and relying party on each verification transaction? So ONE could theoretically store records of who accessed which website, perhaps by mistaken logging configuration or because they were coerced by law enforcement.

Yes this is a great callout. ONE does know the client and relying party on each verification transaction and could theoretically store these records (and your point about strict avoidance of logging PII is very important), but implemented properly, identifying the "who" behind a user after initial verification (the coerced by law enforcement example) would require modifying the server or client-side code to capture plaintext during a future passkey-bound decryption. This is also why I have a goal of open sourcing the server side code that processes the plaintext identity payload and running it in an enclave with verifiable attestation.

> Anyway I appreciate the consideration given to privacy.

Thank you! I appreciate the questions.

mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
also google if you're reading this don't even think about it, patent is pending and my uncle is a lawyer
mikeysight··on Show HN: Anonymous age verification with passkey-powered encryption
check out the demo video! I think you'll like it :) that's the exact user experience (it's built on the same OAuth protocol) but with all underlying data encrypted to your device.
mikeysight··on The Internet Should Be More Like a Liquor Store
Also fair, and there’s certainly an argument to be had there, but it already is law in many cases. Either way, my belief is that it’s not a better outcome to accept the status quo on the implementation side at the expense of privacy while that debate plays out.
mikeysight··on The Internet Should Be More Like a Liquor Store
That's an interesting thought. One thing that comes to mind is that age-gating is often not a cut and dry boolean granting or denying access to an entire application. It's conceivable and even expected that a social media company may want to allow users of any age to access their platform but are legally required to age-gate a subset experience like adult content, gambling etc. I very much like the main street mental model for this, where we default to open access amidst a broad mix of establishments and scope age-gating as minimally as possible vs. having an "adults only" part of town.
mikeysight··on The Internet Should Be More Like a Liquor Store
Totally fair distinction, and good callout. I agree that open access should be the presumption. The liquor store is not meant here as a metaphor for the internet at large, but rather for how the internet should operate in the specific circumstances age verification is legally required.
mikeysight··on The Internet Should Be More Like a Liquor Store
Hi! Author here.

This project has been kicking around in my head since I first heard about the webauthn PRF extension in early 2024. I've slowly chipped away at it since, and finally got things to a shareable state over the summer thanks to a very fun parental leave. Headed back to work tomorrow, so I figure there's no time like the present.

Since the blog post covers the why more than the how, here’s a technical tl;dr:

A client-held encryption key derived during passkey authentication encrypts all sensitive user data prior to persistence so that only the user is able to decrypt and reuse that data on their device. This allows short-lived, privacy-preserving age proofs to be issued to requesting applications (18+, no PII shared) without requiring users to re-upload their documents. The SSO user experience is built on top of the OAuth 2.0 Authorization Code Flow.

Demo video, high-level architecture, and FAQ can be found at https://loginwithone.com

Very open to feedback, and happy to answer any questions about the architecture, PRF/passkey encryption, or anything else!