Live data from Hacker News

Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

blog.google

271–280 of 302 posts

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#271
post #260

Earlier quoted context omitted.

If you are controlling the middle part of the zkp (or at least can validate it), then identification should not be possible through the zkp even if the attestor and and site collude with each other (they could maybe collude based on some other information, like IP address or browser fingerprinting, ofc).

I think if google provides the attestation and they also provide a client side dependency for the site, then they can collect all the data they want. Also, nothing stops a site from having a flow like: 1. Please enter your age 2. Verify that it's correct using a proof The zkp is valid as far as the tech is concerned but the sites can still do whatever they want.

Yeah, if the entities share data they'll share data, but ZKPs give a way to, in principle, verify that they cannot link two parts of that together by doing the verification. I'm not sure I understand your flow example though. If they ask you to enter an age, but will accept a zkp that you're over 18, then you could enter any age over 18 in the first part and they would have no way of knowing.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#272
post #261

Earlier quoted context omitted.

As I understand it, ZKPs can prove both those properties. You can get a certificate from whoever is trusted to verify that you're over 18, and then you can use that to generate tokens that only encode the information 'X has verified that I am over 18' without either the original verifier or the entity you are providing it to being able to link that to the original certificate. See section 2 of this document: https://…

I think that depends on how do you define PII. I suspect the ZKP proof or token is practically unique and related to you, so I could be personal data if you use the definition from GDPR. With ZKP the entity and the original verifier shouldn't be able to match your identity to the ZKP proof or token, but the app on your phone of course can do that. The app probably will be made some government contractor and there is…

The app can be open-source and verified to not be sharing extra info, though. Of course if no-one bothers to use the verifiable version of it, then it's all pointless, but this is true regardless (they could also just not use ZKPs).

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#273

Earlier quoted context omitted.

The web has not had age gating via large-scale government coercion since its inception. To claim that it's absurd to think we can do without it is to detach from that reality, and is itself absurd. The irony.

I am not making an argument based on tradition. I couldn't care less that the web has not been government-gated for the past X years, because through this logic you should adhere to any dumb tradition or custom humans have ever had. I am concerned with the present and the future of the web's impact on the world, which of course requires government intervention like any other big phenomenon or technology in the histor…

> I am not making an argument based on tradition.

I know, and neither am I. Perhaps you misread my comment.

> I couldn't care less that the web has not been government-gated for the past X years

That is clear.

> because through this logic you should adhere to any dumb tradition or custom humans have ever had

Not only is that statement a non-sequitur, since neither of us is making an argument based on tradition, it's also entirely irrelevant.

> I am concerned with the present and the future of the web's impact on the world, which of course requires government intervention like any other big phenomenon or technology in the history of humanity.

An assertion that is a) going beyond the subject, thus creating a straw man, and b) when applied to that actual subject, completely undermined by my comment.

My actual comment, not the one you appear to have decided to respond to that I haven't written, wouldn't write, and thus doesn't exist.

> Not only is your assumption false, since in its first years the web was only accessible to academics so the gating was implicit

The subject is *explicit* age gating. Nothing implicit, and nothing that isn't age gating is relevant.

> Do you know what's behind the cables that carry your bytes? The ICANN? The IANA? I hope you never do, if you dislike government involvement this much

Firstly, that is snark, but fair's fair I suppose. The irony.

Secondly and much more importantly, I dislike age gating via large-scale government coercion, the subject of this discussion.

Could you respond to that? Specifically, age gating via large-scale government coercion.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#274

Earlier quoted context omitted.

[flagged]

So can you give an example of a crazed man-hating feminist woman engaging in a mass shooting? Or just of a woman engaging in a mass shooting (alone, not with a man) in the last, say, 10 years? 20 years? 50 years? Because I can definitely give you examples of incels doing this. Not a huge amount, mind you, but at least some.

I think men hating women don't usually do mass killings. They mostly kill specific men they hate the most.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#275

Earlier quoted context omitted.

> That's where the mass shooters evidently come from. Bollocks. European teenagers watch just as much porn and play GTA at age 10 and yet we don't end up having 12 children a day die from gun violence [1]. Note, I'm not an anti-gun nut, I think German and British anti-gun laws are ridiculously strict. But the American way of dealing with guns is equally bad. [1] https://www.sandyhookpromise.org/resources/gun-violence…

> we don't end up having 12 children a day die from gun violence Note that this definition of "children" includes ages up 24 years old. Not that the US doesn't have a gun violence problem, but pretending 24 year olds are "children" in order to gain a better sound bite doesn't help anybody.

If you look at the actual statistics there are 1300 annual homicides killing children which amounts to 3.5 children + teenagers a day.

Then there are gun suicides which I would not count as gun violence, amounting to another 3.5 children + teenagers a day.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#276

Earlier quoted context omitted.

[flagged]

Incel is a subculture.[1] [1] https://en.wikipedia.org/wiki/Incel

The point is that virgin men or single men get called "Incel", because of how it stings as an insult, not because they are part of a subculture or have the mindset of that subculture.

Imagine being lumped in with crystal meth addicts because your friend gave you a cigarette once.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#277

If you need personalized government attestation to visit a site, then the government has the ability to dynamically deny and rescind your individual access to any site that adopts age verification, at any time. Once adult sites adopt the system, it will creep over to any site wanting to limit their liability. Banks. Business services. Eventually almost everyone. Liability the government will dramatize and escalate. Y…

We don't need age attestation or any kind of identity attestation, period.

We definitely need identity attestation in some places. A basic example is when authorising tax return payments. Or when opening a line of credit. Also when getting e.g. a concealed carry license. And similar for government agents executing search warrants, tow truck drivers picking up cars, etc.

Identity attestation isn’t a bad thing per se. It’s just something that can be abused.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#278
post #192

Earlier quoted context omitted.

I have some experience with zkp, so I’ll try to answer your question to the best off my ability. First on the terminology, the “attester” in this case I assume is whoever is anchoring the data or issued the credential you’re trying to prove. For the canonical example, let’s say you’re trying to prove age >= n via a government ID. 1. The site does not know who you are. This is the whole point. You generate a mathemati…

Does the "attester" knows who is requesting the information? Can they map which places requests which person?

The attestor gives you a credential once. You can think of it as a dob (in e.g. days since 1900) with a digital signature.

Then when you want to access something age gated, you locally generate a proof that says “I have a credential signed by X, with DoB N, and N The attestor isn’t involved so doesn’t learn anything. The Verifier only learns the public information, and generally won’t be able to tell if two proofs are made with the same credential.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#279
post #212

Earlier quoted context omitted.

I do. I’m going to take a wild guess that you are an old head like me, male, and lived your youth in the wonderful internet free of commercialisation of human interaction, free to roam and find new cool things and people, a wonderful library of Alexandria to learn and spend time in. Discuss what the experience was/is to zoomers and younger, especially girls. Did you try to play a silly online game with your friends w…

you said listen to the kids, but if you actually ask kids they will tell you they want a way to block predators and bullies. they want to restrict interactions with specific people or groups on their own terms because thats where all the real harm comes from. they do not want whole sites or categories of content to be blocked. and even if you think kids dont understand it enough to make that choice for themselves you…

Unfortunate fact is that many victims consider predators manipulating them ”friends”. That’s how grooming works. We have discussed the safety of online spaces for 20-30 years now, always hearing the whatever okatform ”doing their utmost for the protection of children bla bla bla” and nothing changes. Meta, Snapchat and various games like Roblox could wipe this issue out of existent today if they wanted to. They won’t.

The fact is that we as a society have so far put the convenience and entertainment of adults before well-being of children and others, who are in the most weakest position.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#280

It is suspicious to me that "age assurance" is trending EXACTLY as AI agents become capable of autonomously operating a personal computer in the same way a human office worker would. I'm afraid "age assurance" has nothing to do with "the children".

The point of ZKP in EU wallet is that it separates checking age and privacy. You can both give a proof your age and not lose privacy.

A significant risk with ZKPs is that they can make a lot of explicit control rules palatable by making the side effects much less extreme.

If a company can come up with a reasonable reason to check something, then a ZKP enables that check without wider harm to privacy. But it still gives the narrow harm to privacy that otherwise wouldn’t exist.

Put differently, privacy concerns have shielded us not just from surveillance, but also from powerful control. Control in the form of “you are only allowed X if you meet criteria Y”. With ZKPs, that shield of “why would I tell you enough information to determine Y” stops working. But those conditions on X are harmful more broadly.

Take the US border checks of Social Media. Are those more OK if all of a sudden there’s a ZKP you have to give of never having called Trump a cunt in any private message?

Post reply on HN