Is it completely impossible to do age verification without compromising privacy?

9 months ago by Sheridan to c/nostupidquestions

To be clear, I'm not advocating for online age verification. I'm very much against it in any form. I'm just curious from a technical standpoint if it's possible somehow to construct an accurate age verification system that doesn't compromise a user's privacy? i.e., it doesn't expose the person's identity to anyone nor leaves behind a paper trail that can be traced to that person?

SorteKanin 142 points 9 months ago

In principle it should be possible to do a zero-knowledge proof.

This means that the website asking for age verification asks a yes/no question like "Is this user 18+?" and the age verification service (like a digital ID provided by the government or whatever) answers "yes" or "no" accordingly, but without telling anything else about the user. Also, the verification service should ideally not know who asked for the age verification.

So the site you want to visit only knows the thing they need to know: Whether you are 18+ or not. Nothing else. And the age verification service only knows somebody asked for age verification and provided the answer, but do not know which site you visited.

This is all possible, but I don't have high hopes this is the intended implementation of any government seeking age verification, so don't get your hopes up.

path: 0 20710195, hotness: undefined, score: 142, children: 15
birdwing 25 points 9 months ago

The one who asked the verification service also shouldn't know who the verification service is, imho.

path: 0 20710195 20710285, hotness: undefined, score: 25, children: 3
SorteKanin 33 points 9 months ago

I'm not sure that is feasible, because in order to trust the answer, I feel the asker must know and trust the one providing the answer. It sounds like you're imagining a system with many different ID providers? What prevents me from creating my own provider that just answers "Yes", even for people under 18? If the site asking does not know it is my fake ID service providing the answer, I'm not sure they can trust any answer.

But I won't pretend to be an expert on this topic, so perhaps it is feasible somehow.

path: 0 20710195 20710285 20710432, hotness: undefined, score: 33, children: 1
halcyoncmdr 8 points 9 months ago

the asker must know and trust the one providing the answer.

This is possible if there's a central authority for that that everyone can agree to trust, like the government records directly. The issue is ensuring the rest of the chain remains anonymous so the only thing the authority gets is the request that an undisclosed service is verifying John Doe is 18+ and nothing else. And that's not something many governments are going to want to allow with the increasingly alarming amount of authoritarian leadership.

path: 0 20710195 20710285 20710432 20713920, hotness: undefined, score: 8, children: 0
Candice_the_elephant 1 point 9 months ago

Or the government sets up an age verification service that doesn't store logs and only reports numbers in aggregate. The restricted site sends you and a unique id off to the government service, you verify there and it hands back the id & a yes/no token to the site.

The government already has nearly all the tools to make this happen. They already have id verification services to use & web front ends to copy. Just build the public API and insist restricted sites use it.

path: 0 20710195 20710285 20747982, hotness: undefined, score: 1, children: 0
chicken 22 points 9 months ago

There are some pretty strong arguments that even zk proof is a flawed way of preserving privacy though, in a variety of ways. It prevents pseudonymity by enabling one-user-one-account, and it leaves users vulnerable to being coerced to reveal their full online activities by handing over cryptographic keys.

path: 0 20710195 20713609, hotness: undefined, score: 22, children: 3
Wren 13 points 9 months ago

Got ready to read some bullshit,

Vitalik Buterin

nevermind. But damn, what a great read. I haven't given much thought to on-chain ID in years and he lays it out pretty well. Still sounds like encrypted tokens are the way to go, but we all need to have multiple forms for it to protect anonymity.

path: 0 20710195 20713609 20714054, hotness: undefined, score: 13, children: 2
chicken 6 points 9 months ago

If there's one person who knows their applied zk proofs, it's that guy.

path: 0 20710195 20713609 20714054 20714626, hotness: undefined, score: 6, children: 1
quick_snail 2 points 9 months ago

Not monero or zcash devs?

path: 0 20710195 20713609 20714054 20714626 20724257, hotness: undefined, score: 2, children: 0
AtHeartEngineer 8 points 9 months ago
path: 0 20710195 20721448, hotness: undefined, score: 8, children: 0
quick_snail 4 points 9 months ago

Does that mean the government sees all the sites I've visited?

path: 0 20710195 20724230, hotness: undefined, score: 4, children: 1
SorteKanin 5 points 9 months ago

No, that's what I wrote as well. The identity service would not know what sites were visited or ideally not even how many sites were visited.

path: 0 20710195 20724230 20725309, hotness: undefined, score: 5, children: 0
perviouslyiner 2 points 9 months ago

doesn't this just raise the authentication requirements? like in the uk we got added checks for who was could work, and lots of deliveroo drivers shared the login + password of someone they knew who was verified.

path: 0 20710195 20710907, hotness: undefined, score: 2, children: 2
Hoimo 4 points 9 months ago

You could make it single-use tokens and rate limit individual users when they request too many tokens in a short time. Someone could still share their tokens with a friend, but it doesn't scale to where thousands are verifying with some stranger's id.

path: 0 20710195 20710907 20728585, hotness: undefined, score: 4, children: 0
Beacon 2 points 9 months ago

I think it should be easy to identify when an account is being shared. For example if it's used from different ip addresses within a short amount of time

path: 0 20710195 20710907 20712339, hotness: undefined, score: 2, children: 0
Strider 2 points 9 months ago

Indeed, technologically it is absolutely possible in multiple ways.

But the tempting possibilities of doing more than that are just too great.

path: 0 20710195 20718520, hotness: undefined, score: 2, children: 0
Zachariah 57 points 9 months ago

Even if it works, it’s a solution without a problem. If I can afford internet access, I am mature enough to see anything on the internet, and I am mature enough to decide which users can access my internet-connected network and whether they can have access to the whole internet. That’s all the age verification needed ever.

The request for age verification by each website is purely about unnecessary control and censorship.

path: 0 20713958, hotness: undefined, score: 57, children: 5
quick_snail 1 point 9 months ago

Internet access is like $1 in most countries (Sim card data).

I don't know about you, but the tooth fairy gave me enough money to pay for internet access before my skull was old enough to finish growing adult teeth...

path: 0 20713958 20724196, hotness: undefined, score: 1, children: 4
Zachariah 9 points 9 months ago

And you had the capacity to pay for internet access?

path: 0 20713958 20724196 20727951, hotness: undefined, score: 9, children: 3
quick_snail 3 points 9 months ago

You fucking walk 20 meters from your doorstep to buy a soda and a gig of data, yeah

path: 0 20713958 20724196 20727951 20732455, hotness: undefined, score: 3, children: 2
Zachariah 10 points 9 months ago

Sounds like you’re mature enough for porn then.

path: 0 20713958 20724196 20727951 20732455 20732606, hotness: undefined, score: 10, children: 1
ininewcrow 44 points 9 months ago

The problem is not the system or the idea of age verification

The problem is that no one on earth can be trusted with that level of monitoring, control and power.

path: 0 20710403, hotness: undefined, score: 44, children: 9
edgemaster72 17 points 9 months ago

Nah you can totally trust me, I'm too lazy to do anything nefarious

path: 0 20710403 20712073, hotness: undefined, score: 17, children: 5
ininewcrow 13 points 9 months ago

Great! .... the solution to our problems ... let's all trust edgemaster72

path: 0 20710403 20712073 20712263, hotness: undefined, score: 13, children: 3
edgemaster72 15 points 9 months ago

Oh, oh shit, this has backfired massively, I didn't think anyone would go along with it, that's way too much responsibility

path: 0 20710403 20712073 20712263 20712487, hotness: undefined, score: 15, children: 2
ininewcrow 17 points 9 months ago

path: 0 20710403 20712073 20712263 20712487 20712558, hotness: undefined, score: 17, children: 0
some_kind_of_guy 9 points 9 months ago

This is precisely what the chosen one would say!

path: 0 20710403 20712073 20712263 20712487 20716309, hotness: undefined, score: 9, children: 0
original_reader 11 points 9 months ago

Wait until you have that power and you're made offers that are hard to resist.

path: 0 20710403 20712073 20712936, hotness: undefined, score: 11, children: 0
AtHeartEngineer 4 points 9 months ago
path: 0 20710403 20721487, hotness: undefined, score: 4, children: 2
ininewcrow 3 points 9 months ago

Like I implied, the problem isn't the HOW to do it.

The problem is in giving any one person, government, corporation or company this amount of power and control.

And because it's so powerful, no one who had it would want to give up control by making it anonymous or in objectively protecting privacy for the user.

path: 0 20710403 20721487 20723466, hotness: undefined, score: 3, children: 1
AtHeartEngineer 4 points 9 months ago
path: 0 20710403 20721487 20723466 20724350, hotness: undefined, score: 4, children: 0
groet 31 points 9 months ago

Super easy. Technology has existed for quite some time and was already used in the encrpytion of web traffic.

Basically: you sign up with your "age verification institution" (ideally a service of your government because they have your ID anyway and no profit motive). This involves createing a private key (reaaaaaaaaaaly long password that is saved in a file on your device) and saving the public key with that institution. They also check your ID to ensure your identity and your age.

When you want to visit a 18+ website, the website sends you a nonce (loooooong random number). You take that nonce and send it to the verifier, along with a signature of your private key (and the age they want you verified against). The verifier verifies your signature using your public key. They then sign the nonce with their own private key, thereby verifying, that you, the owner of your private key (whos identity and age they have verified) are above the asked age theshould. You then send the signed nonce back to the 18+ website and they can verifiy the signature to confirm that a trusted age verifier has verified your age.

The site never has access to your identity and the verifier never knows which site you visited, only that you wanted to visit a website that wants to know if you are of a certain age.

(The corresponding technology was used for OCSP Stapling in TLS verification ... and has been discontinued last year because nobody was using it ...)

path: 0 20735823, hotness: undefined, score: 31, children: 8
billwashere 4 points 9 months ago

Technically this works EXCEPT the required third party. Either it’s the government and you have to trust them with information of knowing everything that required age verification or its separate company that can and would sell your data to data brokers. Being free and NOT the government seems mutually exclusive.

path: 0 20735823 20737049, hotness: undefined, score: 4, children: 6
groet 9 points 9 months ago

The verifier does not have the information which sites you use. That's the point of the setup. All communication goes through you, never the site to the verifier directly. You only pass cryptographic values between them that does not include identifiable information (neither about you to the website, nor about the website to the verifier). The verifier knows who you are, the website knows that you are old enough. Nothing else.

path: 0 20735823 20737049 20737116, hotness: undefined, score: 9, children: 1
billwashere 3 points 9 months ago

Oh I missed that separation before. Ok my bad.

path: 0 20735823 20737049 20737116 20737215, hotness: undefined, score: 3, children: 0
Natanael 4 points 9 months ago

Zero-knowledge proofs still require that third party but only once, to issue it initially. Then the user can issue their own proofs locally

path: 0 20735823 20737049 20739368, hotness: undefined, score: 4, children: 2
billwashere 2 points 9 months ago

So it’s like generating a CA and then signing your own certs.

path: 0 20735823 20737049 20739368 20739590, hotness: undefined, score: 2, children: 1
Natanael 3 points 9 months ago

More like getting a TLS domain cert from a CA both sides recognize, but yeah

path: 0 20735823 20737049 20739368 20739590 20742873, hotness: undefined, score: 3, children: 0
Knock_Knock_Lemmy_In 1 point 9 months ago

You can use a government issued certificate to generate your own age proofs without their involvement.

path: 0 20735823 20737049 20740503, hotness: undefined, score: 1, children: 0
gandalf_der_12te 4 points 9 months ago

I doubt this doesn't actually leave a paper trail.

At some point, you send that nonce to an age-verifier service. So they can keep track of it, and if the 18+ website you visited at some point later wants to know your identity, they can ask the age-verifier service who asked for that nonce to be signed.

This involves that two organizations are corrupt, however: both the 18+ website and the age-verifying service. Law could mandate that they both cooperate, however, thus creating a single point of (privacy) failure.

I still believe it is doable, however. Check my other comment involving a piece of paper that is drawn from a box. My method relies on the fact that the age-verifying service doesn't actually know which code they gave you, just that they gave you one. For digital services, seevices can always keep track of their input/output, which is not always possible in real life.

path: 0 20735823 20743173, hotness: undefined, score: 4, children: 0
ameancow 19 points 9 months ago
path: 0 20721905, hotness: undefined, score: 19, children: 1
sleen 2 points 9 months ago
path: 0 20721905 20745429, hotness: undefined, score: 2, children: 0
Blackmist 18 points 9 months ago

It can. Zero knowledge proofs have been around a while and are ideal for this.

They'll try not to have that because data gathering is what they're after, not keeping little Timmy from seeing some tits.

path: 0 20734771, hotness: undefined, score: 18, children: 0
blaggle42 15 points 9 months ago

Yes. Look up "zero knowledge proofs"

path: 0 20722247, hotness: undefined, score: 15, children: 2
blaggle42 21 points 9 months ago

I mean "no, look up zero knowledge proofs"

path: 0 20722247 20722251, hotness: undefined, score: 21, children: 1
Darkenfolk 8 points 9 months ago

Yesn't

path: 0 20722247 20722251 20725283, hotness: undefined, score: 8, children: 0
DeathByBigSad 15 points 9 months ago

Its possible.

Open source front-interfacing app + a secure element thing in the backgound.

You download an app. You verify your identity, then the app sets up a OTP thing with the shared secret seed lasting for 30 days. But every 30 seconds the OTP changes. Everyone doing a verification in these 30 days gets the same exact secret seed.

The seed hides in the secure element of your device. (it won't be impossible to extract, but the average kid is not gonna be able hack a secure element) Every 30 seconds, it releases the new OTP to the Open source app. The app doesn't connect to the internet once the OTP has already been set up. So nobody knows if you actually view the OTP code.

So the government only knows you have the verification OTP set up not which websites you visited, the website only knows you have a valid OTP from the government, but you could be any of the people in the past 30 days (which the company don't even have access to).

Even if the company and government cooperates, they could only pin down the time of website registration and that you are one of the millions of people that did the verification and requested a OTP Seed.

(Idk the exact terminology for these things, but hopefully I make sense)

path: 0 20710174, hotness: undefined, score: 15, children: 1
anton 7 points 9 months ago

The seed hides in the secure element of your device. (it won't be impossible to extract, but the average kid is not gonna be able hack a secure element).

But only one person needs to "hack" it on their device to publish the key, allowing everyone to use it without "hacking" their own device.

You can't store a key on a device and keep it safe from the owner.

path: 0 20710174 20710896, hotness: undefined, score: 7, children: 0
Modern_medicine_isnt 14 points 9 months ago

Nope, you always need a middle man to do the verification. That middle man has too much information.

Also, if you could solve for the middle man, there is no way to know the user belongs to the ID. It can easily be stolen.

path: 0 20726111, hotness: undefined, score: 14, children: 12
Saledovil 4 points 9 months ago

We could just make the middle man somebody who already needs that information, e.g. the IRS.

path: 0 20726111 20734711, hotness: undefined, score: 4, children: 1
Modern_medicine_isnt 2 points 9 months ago

You could, but that wouldn't address OPs question. The IRS is known for giving info to other parts of the government to aid in prosecution. And the gov has shown they are terrible at cyber security, so you might as well just post your browser history on the web.

path: 0 20726111 20734711 20741195, hotness: undefined, score: 2, children: 0
dickalan -22 points 9 months ago

I figured you were wrong so I asked an AI and it confirmed what the people below you were saying, you really do seem to be talking straight out of your ass

Yes, it is technically possible to build an accurate, high-confidence age-verification system that does not compromise privacy in the traditional sense (i.e., no central database of IDs, no name/address/DOB stored by the site, no paper trail that can be subpoenaed or leaked). The core tool that makes this feasible is zero-knowledge proofs (ZKPs), specifically age-based ZK proofs.

How a privacy-preserving age check actually works in 2025

  1. User proves age to a trusted credential issuer once
    • Government digital ID (e.g., EU eIDAS wallet, some U.S. mobile driver’s licenses, Yoti, ID.me, etc.)
    • The issuer cryptographically signs a statement like “This private key belongs to someone born before 2007-11-27” without ever revealing the exact birthdate. User generates a zero-knowledge proof
    • Using their phone or browser, they create a proof that says:
      “I have a valid credential signed by [Trusted Issuer] that confirms I am 18+ (or 21+).”
    • Nothing else is revealed: no name, no exact age, no birthdate, no issuer identity if you want to go fully anonymous. Website verifies the proof in <1 second
    • The site checks the cryptographic signature and that the policy (“18+”) is satisfied.
    • It learns literally nothing else about the person.

Real-world implementations that already exist or are in late-stage pilots (November 2025):

  • Worldcoin’s World ID “age 18+” orb-verified credential + ZK proof
  • Polygon ID / zkBridge systems used by some adult sites
  • SpruceID + Ethereum Attestation Service kits
  • Gitcoin Passport + ZK age attestations
  • Proof-of-Humanity + age minimum circuits
  • Yoti + ZK prototype (demoed 2024–2025)

Remaining practical hurdles (why it’s not universal yet)

  • User has to have a compatible digital credential in the first place (adoption still <30% in most countries)
  • Friction: first-time setup takes 2–10 minutes instead of 3 seconds
  • Most adult sites don’t want to pay the (tiny) gas/verification fee or integrate the SDKs
  • Regulatory gray zone in some jurisdictions that still mandate “know your customer” records

Bottom line
Technically: Yes, 100% possible today with zero-knowledge age proofs.
Practically: It exists, works, and is slowly rolling out, but the porn industry and most social platforms still prefer cheap/frictionless (but privacy-invasive) methods or just do nothing.

So the top reply in your screenshot (“you always need a middle man with too much information”) is outdated — cryptography has already solved the “middle man” problem. The real blocker now is deployment inertia, not theory.

path: 0 20726111 20729116, hotness: undefined, score: -22, children: 9
Modern_medicine_isnt 12 points 9 months ago

Read back what you wrote. Your first line was about a trusted credential provider. Thats a middle man. Then you talk about creating a proof. Guess what, that phone and browser are known to spy on you excessively. That's another middle man. And odds are that same phone or browser it what you will use to access something that needs the verification. So the same phone or browser has all parts of the information.
And of course it's pointless because anyone could steal an ID and get themselves a key. Or steal your phone... so it wouldn't even prove anything.

path: 0 20726111 20729116 20730495, hotness: undefined, score: 12, children: 2
jabberwock 0 points 9 months ago

I'll address the second objection first regarding the phone or browser. You're always going to rely on some technology for the solutions that use cryptography, you just can't do those calculations long-hand realistically. That said, look up frameworks like CTAP that allow a potentially untrusted user terminal, like a browser, to interact with a trusted hardware token. Those hardware tokens can be made fairly tamper-proof, see FIPS authorized Yubikeys, such that the phone is pretty much removed from the attestation process. Yes these can still be stolen, but they make hardware keys that are fingerprint authenticated and the biometric stays on the device. Doesn't get much more self-sovereign than that.

The existence of a trusted credential provider is a challenge. Fully self-sovereign credentials need to either be trust on first use or validated against a larger system everyone participates in. Even if we had some system of birth certificates tied to a distributed ledger, we would have to trust the third party recording that certificate in the first place, be it a hospital, doctor, or state entity. These trust and proof systems don't create the trust, they just allow us to extend that trust from one claimant to a verifier. Whether you place that trust in the state, an individual, or an independent third party is up to you.

path: 0 20726111 20729116 20730495 20732743, hotness: undefined, score: 0, children: 1
Modern_medicine_isnt 2 points 9 months ago

So, you have fully backed my response. OP didn't ask if it was possible with some caveats. I understand a (at a high level) the technical options that can get close to what OP asked for, but it fundamentally just isn't possible without caveats.

path: 0 20726111 20729116 20730495 20732743 20741320, hotness: undefined, score: 2, children: 0
njm1314 11 points 9 months ago

Just for your edification anything you say after "so I asked an AI" is going to be ignored by most people. It just tells me everything that comes next is not going to be worthwhile. Might as well tell me your palm reader told you something.

path: 0 20726111 20729116 20732883, hotness: undefined, score: 11, children: 1
dickalan 1 point 9 months ago

Ok

path: 0 20726111 20729116 20732883 20740111, hotness: undefined, score: 1, children: 0
phoenixz 7 points 9 months ago

you're talking out of your ass so I asked an AI

Pot, you are black! Signed, kettle

path: 0 20726111 20729116 20735643, hotness: undefined, score: 7, children: 0
TechLich 4 points 9 months ago

The big flaw in this strategy is that once you have set up a signed anonymous key from the government and you can make zero knowledge proofs with it, there's nothing stopping you from distributing that key to every kid who wants it. If it's in the browser or an app, etc. you can publish that signed key for anyone who wants to be over 18.

PKI only works if the owner of the private key wants it to be private. It's effective for things like voting or authenticating because the owner of the key doesn't want anyone else to be able to impersonate them. But if it's only for age...

At that point, it might as well just be a file that says "I pinky promise that I'm over 18" that the government has signed and given to you.

path: 0 20726111 20729116 20735038, hotness: undefined, score: 4, children: 2
jabberwock 2 points 9 months ago

Could tie it to something like a biometric. That and storing it on a write-only device would keep it from being shared too wide. The trickiss to tie it to a true multi-factor and not just something you have (if unencrypted) or something you know (if ASCII armored).

path: 0 20726111 20729116 20735038 20736587, hotness: undefined, score: 2, children: 1
coriza 2 points 9 months ago

Then it adds barrier to entry. If it costs money it will be a problem for the more vulnerable population. If it is free and you can have as many as you want it is gonna be abused, if there is a limit it again starts to be a problem.

path: 0 20726111 20729116 20735038 20736587 20744423, hotness: undefined, score: 2, children: 0
grandel 12 points 9 months ago

No, It should be a browser setting. If parental controls are enabled, access should be denied to the site.

path: 0 20718466, hotness: undefined, score: 12, children: 0
qevlarr 11 points 9 months ago

It is possible, but the real goal is about removing anonymity altogether

path: 0 20735782, hotness: undefined, score: 11, children: 0
ComradePenguin 9 points 9 months ago

Yes. There are many solutions.

Maybe the absolutely easiest to implement is just a signed message from an authority (gov.). You click a button on the website that requires verification, get a new tab to a gov. site with no identifiers from the site redirecting you and get a message you copy. The copied message is then pasted in to the site requiring verification. The site can then verify the message at their servers.

path: 0 20719656, hotness: undefined, score: 9, children: 6
Scirocco 14 points 9 months ago

Hey benign and honorable govt!

Please tell the website "kill-your-govt .net" that I am old enough to join the revolution!!!

Kthxbai

edit: if this was pasted in both directions AND we trust that there is no identifying information in either 'secret' message, might work. Normies will not like the ctrl-c/ctrl-v workflow though.

path: 0 20719656 20721697, hotness: undefined, score: 14, children: 0
ameancow 9 points 9 months ago
path: 0 20719656 20721741, hotness: undefined, score: 9, children: 1
quick_snail 3 points 9 months ago

See also: timing attacks

path: 0 20719656 20721741 20724171, hotness: undefined, score: 3, children: 0
DoctorPress 5 points 9 months ago
path: 0 20719656 20720892, hotness: undefined, score: 5, children: 2
Uruanna 2 points 9 months ago

How about

Middleman anonimizer, pornhub sends the message to a middleman, the middleman puts its own token on the request, sends that to the gov, the gov responds yes/no to the middleman on the authenticity of the message, the middleman forwards the response to pornhub. The gov doesn't see pornhub, pornhub only gets the yes/no response, the middleman only sees the message with no ID and the response as well as the site.

Requires a separate middleman maintained by who the fuck knows. Pornhub keeps your IP, the gov keeps your name, the middleman only knows the number of visitors on pornhub.

path: 0 20719656 20720892 20721071, hotness: undefined, score: 2, children: 0
ComradePenguin 1 point 9 months ago

If they can trace it, why would they need the code to do it? They know who you are already

path: 0 20719656 20720892 20726125, hotness: undefined, score: 1, children: 0
Natanael 9 points 9 months ago

Correct, as a cryptography nerd I can assure you that you MUST at minimum have a trusted verifier which met you in person at some point (such as whatever office you get your physical ID card at) and they have to have your information.

And then you're trusting both Secure Element hardware and fancy cryptography where both must be flawless in order to protect the end user's side of it, all while the end user now carries much more personal information with them than before

path: 0 20739320, hotness: undefined, score: 9, children: 3
Knock_Knock_Lemmy_In 3 points 9 months ago

The verifier does not know what exactly you are proving, when you are proving it or to whom.

The service provided by the verifier is equivalent to a stamp on a piece of paper.

path: 0 20739320 20740479, hotness: undefined, score: 3, children: 2
Natanael 2 points 9 months ago

Bad terminology choice, I meant the cert issuer. Need to revise the language later. I was thinking of it in terms of who verifies your IRL identity. The issuer can only issue the cert after you met them and they checked your documentation, etc

path: 0 20739320 20740479 20742898, hotness: undefined, score: 2, children: 1
Knock_Knock_Lemmy_In 2 points 9 months ago

In any system there has to be some source of truth to base the data on. Otherwise people can claim anything .

path: 0 20739320 20740479 20742898 20745291, hotness: undefined, score: 2, children: 0
daniskarma 8 points 9 months ago

It's possible with certificates and 2fa issued by a government, which already have all your data, that would only verify that you are over 18.

We already have that in Spain, sort of. We have a government app where you have a digital id stored and you can make it create a verify qr that only shows if the user is over 18 or under 18, no more data. The qr only last 5 minutes active.

It is necessary? Not for internet access. That's a duty of the one paying for internet in the household, not the government. If they have underage kids under their responsibility it's their duty to make sure that they get good education about what to see and what not and restrict access if needed. Having the government to universally interfere everyone it's just plain bad.

path: 0 20718755, hotness: undefined, score: 8, children: 0
Nighed 7 points 9 months ago

The government knows who you are. They know your age, your address and know you exist (probably).

You go to a site that requires ages verification. You say:please verify me with the government portal. You go to that portal to get a temporary id code to give to the site. The website says to the gov portal give me the name and age of the user with this temp ID. You approve that access. Portal sends age (or an is over 16/18/21 etc flag) to the site.

  • Gov portal doesn't need to know who the site is.
  • You don't provide a unique ID to the website, just a temporary one.
  • as if codes are temporary, you must have access to the id/login now, not just at some point
  • Site only gets the data you approve/it requested,.not everything.

The process can do with some streamlining, but should work in practice?

path: 0 20710536, hotness: undefined, score: 7, children: 1
AtHeartEngineer 2 points 9 months ago
path: 0 20710536 20721850, hotness: undefined, score: 2, children: 0
birdwing 7 points 9 months ago path: 0 20710270, hotness: undefined, score: 7, children: 0
ilinamorato 5 points 9 months ago

I'm inclined to say no. Reducing the problem down to its most basic parts: Alice is authorized to talk to Bob, but Bob doesn't know that. How can Alice prove it?

Bob has to assume that anyone asking to talk to him could be Mallory, who isn't authorized to talk to him but will always answer "yes" if asked whether she is. So the authorization he gets has to be from a trusted third party; it can't come from Alice.

Grace is a trusted third party. If Alice doesn't care about privacy, and is okay with Grace knowing that Alice talked to Bob and with Bob knowing Alice's identity, Alice can just tell Bob, "here's proof that I'm Alice. Show this to Grace and she'll confirm that I can be here." This is SSO, essentially.

If Alice doesn't want Bob to know who she is, but is ok with Grace knowing that Alice talked to Bob, she can ask Grace to give her a secret code, and give that code to Bob, who can check with Grace to know whether or not that code corresponds to someone who is authorized.

If Alice doesn't want Grace to know that she's talking to Bob, though, she runs into a problem. Because there's no way for Grace to send Bob a message without knowing who Bob is, he can't ask anonymously, and because there's no way for Grace to confirm that Alice is authorized without knowing who she is, Grace will always know that Alice has asked for authentication to talk to Bob.

Adding Dave in as a trusted fourth party could solve the problem—Alice asks Dave to check with Grace, and lock his answer in a bag with a unique key that only Dave has. Then Grace could give the bag to Bob, who doesn't need to know who Grace is to pass the bag to Dave and ask him to unlock it. But Alice would be trusting that Dave won't keep records on which bag corresponds to which person.

I don't think that's a surmountable problem. I'll have to think about it some more.

path: 0 20733468, hotness: undefined, score: 5, children: 13
Saledovil 4 points 9 months ago

Here's my idea: Bob gives Alice a token, assigning her an unique random number n. Alice goes to Grace and tells her, "Somebody assigned me number n, can you verify that I'm allowed?" Grace then writes: "User n is allowed, signed Grace". Alice then takes this letter and shows it to Bob. Bob now knows that Alice is allowed, but nothing else. Grace only knows that somebody wanted to know that Alice is allowed, not who that somebody is.

Of note here: This system does nothing to protect against an allowed user helping a not allowed user to gain access, but I don't think it's possible to protect against traitorous users.

path: 0 20733468 20734609, hotness: undefined, score: 4, children: 11
Blackmist 3 points 9 months ago

This is called a nonce.

Which as a Brit is a really bad name for anything used to access porn.

path: 0 20733468 20734609 20735952, hotness: undefined, score: 3, children: 1
oftenawake 2 points 9 months ago
path: 0 20733468 20734609 20735952 20741095, hotness: undefined, score: 2, children: 0
groet 3 points 9 months ago

This system does nothing to protect against an allowed user helping a not allowed user to gain access

There is no system in the world that can fully prevent an authorized user to grant access to an unauthorized user. Even with an all time on camera and screensharing I can still find ways to have someone else control my computer while I "authorize" the connection with my face in the camera

path: 0 20733468 20734609 20735879, hotness: undefined, score: 3, children: 1
gandalf_der_12te 1 point 9 months ago

Yeah a small false-positive rate will have to be accepted. This is the same like you can't fully prevent minors from getting access to alcohol. Consider that their older sibling can buy it for them (at an increased price, ofc).

What matters is to keep the rate of false positives reasonably small, i'd say.

path: 0 20733468 20734609 20735879 20743322, hotness: undefined, score: 1, children: 0
gandalf_der_12te 2 points 9 months ago

The problem is that it leaves a paper trail.

Grace also knows what number n got verified, and the identity of the user n. Later, the website can ask the age-verifying service who user n actually was. It requires that the age-verifying service cooperates with the website, though, but this could be mandated by law, which would create a single point of (privacy) failure.

PS: i love your writing style. It's so simple and clear :)

Cryptography is a really complicated subject. You managed to express it very easily understandable.

path: 0 20733468 20734609 20743365, hotness: undefined, score: 2, children: 1
Saledovil 1 point 9 months ago

Yeah, that is a problem.

And thanks for the compliment.

path: 0 20733468 20734609 20743365 20745445, hotness: undefined, score: 1, children: 0
ilinamorato 1 point 9 months ago

That could very well work, yes; but I think that would require Bob verifying Grace's signature, and that would require trusting that Grace didn't make a unique signature that she only used for Alice, and making a note of who verified it.

There might be a way to verify those signatures with public keys in a way that didn't require Bob to tell Grace that he was verifying the signature, which is still rattling around in my brain.

path: 0 20733468 20734609 20736728, hotness: undefined, score: 1, children: 4
Saledovil 1 point 9 months ago

Bob would have to know and trust Grace beforehand. Grace could be the IRS, for example. The idea here being to have somebody who already knows your age vouch for your age.

path: 0 20733468 20734609 20736728 20736898, hotness: undefined, score: 1, children: 3
ilinamorato 1 point 9 months ago

That's not about Bob trusting Grace specifically (that's a premise of the entire operation), it's about trusting that the letter Alice handed Bob was actually signed by Grace.

path: 0 20733468 20734609 20736728 20736898 20738147, hotness: undefined, score: 1, children: 2
gandalf_der_12te 1 point 9 months ago

See my comment in this thread involving drawing a piece of paper from a box in real life. Since nobody knows which piece of paper you draw from a box, if many people do this at the same time, it's impossible to establish an one-to-one mapping between age-verifying tokens and people's identities.

path: 0 20733468 20743287, hotness: undefined, score: 1, children: 0
sharkfucker420 5 points 9 months ago

It's possible but it would defeat the purpose of age verification

path: 0 20710244, hotness: undefined, score: 5, children: 1
AtHeartEngineer 1 point 9 months ago
path: 0 20710244 20722085, hotness: undefined, score: 1, children: 0
quick_snail 5 points 9 months ago

Yes, but your government doesn't want that.

path: 0 20724147, hotness: undefined, score: 5, children: 0
gandalf_der_12te 4 points 9 months ago

It is doable, i think. Consider:

You go to your local library. They verify you're above the age limit (like they do at supermarkets when you try to buy alcohol: either look you in the face and recognize you're clearly old enough, or have to show them some kind of id, details vary.)

You pick a code (put your hand in a box and draw a piece of paper at random). Nobody knows what code you picked except you. If lots of people do this at the same time, it's impossible to accurately map codes to people's identity.

You scan the code (like QR code) with your social media app that you use, and it associates the code with your account. Now everybody knows you have a valid code associated to your account, but nobody knows your identity.

(The code could work something like a cryptographic signature, where you can show that you have a valid code without actually revealing the code, so others can't simply copy it. That's a technical detail that you need to leave to the programmers to accurately understand.)

path: 0 20742956, hotness: undefined, score: 4, children: 2
leadore 4 points 9 months ago

That sounds logical, but I think there would be an immediate black market for valid codes that would be sold to minors.

path: 0 20742956 20743252, hotness: undefined, score: 4, children: 1
gandalf_der_12te 3 points 9 months ago

same for alcohol

path: 0 20742956 20743252 20744283, hotness: undefined, score: 3, children: 0
UsedCumSock 4 points 9 months ago
  1. Sign up for age verification platform and upload your government ID on the platform (let's call this platform Age Verifier).
  2. Age Verifier confirms you're an adult, and lists you as an adult in their system.
  3. Age Verifier purges your government ID and any PII on you. The only thing they keep is your basic account details and the fact that they've confirmed you're an adult.
  4. The next time you login to an adult site, you verify yourself by logging into Age Verifier's platform. The adult site confirms with Age Verifier that you're an adult, and you're good to go.

This system probably works, but it's not without its downsides. We'll need a way to confirm that your government ID and PII is actually deleted on Age Verifier's platform. A way to deal with this might be to make sure Age Verifier is never driven by profit so they'll never need to look into selling people's data. Maybe it could be ran by a non-profit? Or perhaps it can be ran by the government? But if you don't trust the government, that could be an issue.

And I can also see an issue where one guy who keeps creating different Age Verifier accounts, verifying that the account is an adult, and then selling that account to people.

path: 0 20710385, hotness: undefined, score: 4, children: 1
xavier666 5 points 9 months ago

We’ll need a way to confirm that your government ID and PII is actually deleted on Age Verifier’s platform.

IMO this is the hardest part to ensure in a transparent manner.

And I can also see an issue where one guy who keeps creating different Age Verifier accounts, verifying that the account is an adult, and then selling that account to people.

The token needs to be time and device sensitive. Should be possible via a hash

path: 0 20710385 20716840, hotness: undefined, score: 5, children: 0
pdqcp 4 points 9 months ago path: 0 20710772, hotness: undefined, score: 4, children: 0
Archangel1313 4 points 9 months ago

It's only possible as long as you trust the people you're giving your information to. So...no.

path: 0 20711626, hotness: undefined, score: 4, children: 1
AtHeartEngineer 0 points 9 months ago
path: 0 20711626 20722140, hotness: undefined, score: 0, children: 0
howrar 4 points 9 months ago

Depends on how reliable you need this system to be. For example, do you need to handle the scenario where an adult verifies their age to access a website, then lets a minor use that website in their place? That would be a much harder problem to solve than if you just need to verify that an adult was present on the other end at one point in time. For the latter, device-based age verification seems to be trivial to set up from a technical standpoint while fulfilling that criterion.

path: 0 20711805, hotness: undefined, score: 4, children: 1
LifeInMultipleChoice 2 points 9 months ago
path: 0 20711805 20712569, hotness: undefined, score: 2, children: 0
QuinnyCoded 4 points 9 months ago

I'd say it's impossible. Minors will ALWAYS find a way around it, even if it involves government IDs. The actual trick is finding if a "are you 18?" box is enough or not.

path: 0 20741393, hotness: undefined, score: 4, children: 0
rowinxavier 4 points 9 months ago

There are tonnes of ways but honestly, the easiest way is to do it at the ISP level. Have an internet connection you don't want used for adult material? Have an opt in service at the ISP to block XXX rated sites and maybe social media. If you are old enough to pay for your own internet you should not be required to jump through hoops to access what you want, but kids should not be thrown onto the internet without guardrails. Some kids will get around it but it would be an active choice, so most kids would not. And to be clear, this would be done at the ISP level where you already have verification of age built in to billing, so no additional privacy concern. Honestly, the fact that this is not the solution is what tells me all of this filtering is not about protecting kids, it is about centralisation and control along with pork barrelling for age verification companies.

path: 0 20735062, hotness: undefined, score: 4, children: 3
sleen 2 points 9 months ago
path: 0 20735062 20745177, hotness: undefined, score: 2, children: 2
rowinxavier 3 points 9 months ago

Yeah, there is a massive difference between a 9 year old and a 14 year old. Someone who is 17 is not necessarily significantly different from an 18 year old, yet we have to draw the line somewhere. I think if you own and pay for the service it should be up to you at a service level, not up to the government to demand a random third party company be accessed to verify ID and so on. That third party company stands to make money while also being a wonderful target for hackers.

path: 0 20735062 20745177 20748816, hotness: undefined, score: 3, children: 1
sleen 2 points 9 months ago
path: 0 20735062 20745177 20748816 20751814, hotness: undefined, score: 2, children: 0
whotookkarl 2 points 9 months ago

There are no registration or registry with individuals' information if guardians use parental controls and adult sites and apps identify themselves as adult for those controls, check what their kids are doing online, and talk with them about dangerous people or content they might see to teach them how to stay safe.

path: 0 20738643, hotness: undefined, score: 2, children: 0
altphoto 2 points 9 months ago

We could go by width of feet... You take a foot picture, it goes to another user temporarily while they sign in. If they think that's an adult then you're in. Then they take a foot photo and the next random user sees their image and they have to judge if the image is an adult. But the image could also be a fake. If they identify a false positive they have to wait 5 minutes. And so on. If others need to login they could judge the same image already identified as adult. If they think its not an adult then that user's logins is set to wait 5 minutes while two other users are snown the image. If those two users think its an adult then the user who said it was not an adult get to wait for 15 minutes. If however those two guys agree with it not being adult then that user gets permanently banned.

path: 0 20732830, hotness: undefined, score: 2, children: 1
altphoto 2 points 9 months ago

The users confirm others at random.

path: 0 20732830 20732836, hotness: undefined, score: 2, children: 0
AtHeartEngineer 1 point 9 months ago
path: 0 20722132, hotness: undefined, score: 1, children: 0
nostupidquestions
nostupidquestions

@lemmy.world

login for more options
49488
6735
6512

No such thing. Ask away!

!nostupidquestions is a community dedicated to being helpful and answering each others' questions on various topics.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must be legitimate questions. All post titles must include a question.

All posts must be legitimate questions, and all post titles must include a question. Questions that are joke or trolling questions, memes, song lyrics as title, etc. are not allowed here. See Rule 6 for all exceptions.



Rule 2- Your question subject cannot be illegal or NSFW material.

Your question subject cannot be illegal or NSFW material. You will be warned first, banned second.



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Questions which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding META posts and joke questions.

Provided it is about the community itself, you may post non-question posts using the [META] tag on your post title.

On fridays, you are allowed to post meme and troll questions, on the condition that it's in text format only, and conforms with our other rules. These posts MUST include the [NSQ Friday] tag in their title.

If you post a serious question on friday and are looking only for legitimate answers, then please include the [Serious] tag on your post. Irrelevant replies will then be removed by moderators.



Rule 7- You can't intentionally annoy, mock, or harass other members.

If you intentionally annoy, mock, harass, or discriminate against any individual member, you will be removed.

Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.



Rule 8- All comments should try to stay relevant to their parent content.

Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- Majority of bots aren't allowed to participate here. This includes using AI responses and summaries.

Credits

Our breathtaking icon was bestowed upon us by @Cevilia!

The greatest banner of all time: by @TheOneWithTheHair!

go to feed...