Live data from Hacker News

Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

blog.google

151–160 of 302 posts

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#151

It is suspicious to me that "age assurance" is trending EXACTLY as AI agents become capable of autonomously operating a personal computer in the same way a human office worker would. I'm afraid "age assurance" has nothing to do with "the children".

>It is suspicious to me that "age assurance" is trending EXACTLY as AI agents become capable of autonomously operating It is not, because your premise is false. This whole thing has been going on for as long as kids have been online. The early 2000s tried (and obviously failed) by using credit cards. The UK tried and failed last decade to ban porn for minors this way. AI tools are probably not even on the radar for t…

> AI tools are probably not even on the radar for the kind of politicians that keep pushing this.

Forget about the politicians for a bit. There still are many regions on the globe where no age verification is mandatory, yet websites chose to implement it anyway. Why, if not for tracking and bots?

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#152

It is suspicious to me that "age assurance" is trending EXACTLY as AI agents become capable of autonomously operating a personal computer in the same way a human office worker would. I'm afraid "age assurance" has nothing to do with "the children".

The point of ZKP in EU wallet is that it separates checking age and privacy. You can both give a proof your age and not lose privacy.

Except that ZKP for sensitive data is far from being a thing, and also, I don't want the fucking government to have anything to do with what sites I access. Period.

Why the hell do I need to login to my digital wallet to access a fucking website???

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#153
post #17

Earlier quoted context omitted.

zero-knowledge proofs are a well-known tool in cryptography [1]. All Google is sharing is the library to implement it. Google would not have access to the information any more than they have access to the bank info of people who use Android or Gmail. [1] https://en.wikipedia.org/wiki/Zero-knowledge_proof

It's my understanding that they are sharing the library but they will also be involved as a facilitator, at least to the extent that people use their identity wallet service. It also seems like they will have access to who you are sharing information with, which seems like the most valuable information for a company in their position, with nothing but a pinky promise that it will not be tracked. Let me know if any of…

You also can't know if Google has broken any of the ZKP promises, or in terms of the field, if Google is cheating and uncovered the secret bits you shared.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#154
post #79

Zero-knowledge seems to be a bit of an oversell here. It is more like you break the knowledge up and only share the relevant parts with each party. And the facilitator (Google) arguably has access to the most information out of any of the parties involved.

Google has pioneered a few technologies where they are the trusted dealer. For example, Private State Tokens. I have written a paper on how to do age verification in a completely privacy-preserving way, and it doesn’t even need zero-knowledge proofs: https://magarshak.com/papers/Personal.pdf

How about not needing to do age verification?

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#155
post #81
post #70

Earlier quoted context omitted.

If you get enough signals like that you can often narrow down a very large cohort of people to an individual. First it's 'over 18?', then it's 'over 25?', and then 'biological sex?', 'employed?', 'enjoys posting on HN?', 'active in the early morning?' and after half a dozen questions, all with binary answers that are safe individually, you can zero in on a 23 year old woman who has a job and posts on HN in the mornin…

Proper ZK proofs don’t work that way. N different proofs will not be linked to each other unless the circuits are written to emit a stable identifier. Obviously if you see a bunch of proofs for known circuits coming from the same IP address then yeah, you can infer a bunch of info from that metadata.

> Proper ZK proofs don’t work that way. N different proofs will not be linked to each other

in theory. How do you do that on paper? How do you "anonymize" this data, to make it so they aren't related to each other?

This is just like Facebook implementing the Signal protocol on WhatsApp. They technically can't access your messages, but they have all the metadata which most of the times will allow someone to infer the content of the conversation.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#156

If you need personalized government attestation to visit a site, then the government has the ability to dynamically deny and rescind your individual access to any site that adopts age verification, at any time. Once adult sites adopt the system, it will creep over to any site wanting to limit their liability. Banks. Business services. Eventually almost everyone. Liability the government will dramatize and escalate. Y…

We don't need age attestation or any kind of identity attestation, period.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#157

Will they not just argue that you could share the assertion, and hence we need a 'trusted' verfication point to establish it is actually you in posession of the zkp token, right now. So turn on that smartphone camera right now and obediently follow our biometric verfication instructions ...

Or even simpler - they can just claim to implement it but still store your data just because. Doesn't seem like government is taking any steps here to try and regulate anything anymore. Possibly not ever again.

There is literally no way of us knowing if Google hasn't chosen to cheat during the ZKP protocol or not. Zero chance.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#158
post #13

I've been trying to figure out how zero-knowledge stuff would work in practice for age verification, where "when issued" (or extremely coarse, like what year), "to whom", and "where it's used" are hidden from everyone except the individual holding the proof (since that's the gold standard, and the only one worth accepting). I get that ZK techniques work, and reveal "nothing". That's useful. But if they reveal nothing…

> But if they reveal nothing, isn't it wide open for abuse? Couldn't one over-18-person's proof become everyone's proof, because they can't tell it's the same proof, and the issuer can't tell where or how often the proof is being used? Yep! This is why the concept of zero knowledge age gating is such a trap for technically minded people. They imagine receiving a private cryptographic object that can be used to anonym…

From my limited knowledge of ZKP I believe there are protocols that don't allow token reuse, i.e., once you consume a token for one round, you cannot reuse it for another attestation.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#159
post #83

Earlier quoted context omitted.

Not that I want my kids looking at porn or violent content, but I’m far more concerned about man-o-sphere influencers than that other stuff.

I had to Google "man-o-sphere". Is it particularly more dangerous or toxic than other identity-based activist communities? Genuinely curious to know

[dead]

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#160
post #70

Earlier quoted context omitted.

This can be used to have zero-proof knowledge of "over 18" or "not over 18". So they don't really get your age, except that you are in two broad ranges.

If you get enough signals like that you can often narrow down a very large cohort of people to an individual. First it's 'over 18?', then it's 'over 25?', and then 'biological sex?', 'employed?', 'enjoys posting on HN?', 'active in the early morning?' and after half a dozen questions, all with binary answers that are safe individually, you can zero in on a 23 year old woman who has a job and posts on HN in the mornin…

Browser fingerprinting can already pinpoint you exactly. We should focus on that.
Post reply on HN