Live data from Hacker News

Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

blog.google

221–230 of 302 posts

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#221
post #13

I've been trying to figure out how zero-knowledge stuff would work in practice for age verification, where "when issued" (or extremely coarse, like what year), "to whom", and "where it's used" are hidden from everyone except the individual holding the proof (since that's the gold standard, and the only one worth accepting). I get that ZK techniques work, and reveal "nothing". That's useful. But if they reveal nothing…

> But if they reveal nothing, isn't it wide open for abuse? Couldn't one over-18-person's proof become everyone's proof, because they can't tell it's the same proof, and the issuer can't tell where or how often the proof is being used? Yep! This is why the concept of zero knowledge age gating is such a trap for technically minded people. They imagine receiving a private cryptographic object that can be used to anonym…

You can fix the leaked token problem if your prover also proves that (a) the private token id is not on the public revocation list, and (b) the token has not yet expired. Use short expirations and auto-renew, this is just to keep the revocation list from growing forever.

Attackers could still compromise the system with proxies, but you can fix that by (a) passing in a random sessionid from the server so proofs can't be replayed, (b) also passing in the server's public key, so a MITM attack will result in proof the server can't verify, and (c) as you mention, using secure hardware on the client, and encrypting communications between that hardware and the server. The secure hardware doesn't have to preclude general-purpose computers; it can work like a yubikey or hardware wallet, just plug into USB or bluetooth.

Without proxies, a leaked key has a minor impact unless it's widely distributed online, in which case it's easy to notice and add to the revocation list.

Tracking clients can be prevented if the client generates a new public key for each session.

Requiring hardware is in one sense a downside, and strong protections for access would have to be part of the law. But giving everyone secure cryptographic hardware that can do key management and zero-knowledge proofs would be a huge improvement for everyone's privacy and security, so it might be a good trade.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#223
post #10

Still, I don't want to gate people based on age. Parents should at least be able to overwrite the age of their child, maybe selectively allow bypasses. My experience with a computer would have been completely different if I was blocked from half of the internet. Especially when I see which kind of content gets blocked.

[deleted]

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#224

Earlier quoted context omitted.

> But if they reveal nothing, isn't it wide open for abuse? Couldn't one over-18-person's proof become everyone's proof, because they can't tell it's the same proof, and the issuer can't tell where or how often the proof is being used? Yep! This is why the concept of zero knowledge age gating is such a trap for technically minded people. They imagine receiving a private cryptographic object that can be used to anonym…

From my limited knowledge of ZKP I believe there are protocols that don't allow token reuse, i.e., once you consume a token for one round, you cannot reuse it for another attestation.

Which requires some record keeper transaction.

Which turns into a handshake with the centralized entity, the government.

If every token is single use then you also need to get them all from the government, either on demand or in bulk. They can then be sold.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#225
post #220

"ZKP makes it possible for people to prove that something about them is true without exchanging any other data. So, for example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all." But not "...without sharing anything else even when setting up your token." Can I prove that some cryptographic token A) doesn't contain any PII and B) that the token itself can't b…

Of course not? The idea would be a government (who already has your age data for example) will allow you to create a signed message and the platform you are verifying your age to doesn't know who you are, what age you are but that you are of age

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#226

Earlier quoted context omitted.

I had to Google "man-o-sphere". Is it particularly more dangerous or toxic than other identity-based activist communities? Genuinely curious to know

Yes, a lot of it involves denigrating women and an entitled and very rigid attitude towards the male place in society (alphas etc). This is incredibly toxic for young men growing up and the women they interact with. Some of the more prominent proponents are actual pimps (the Tate brothers).

[flagged]

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#227
post #192

Earlier quoted context omitted.

I have some experience with zkp, so I’ll try to answer your question to the best off my ability. First on the terminology, the “attester” in this case I assume is whoever is anchoring the data or issued the credential you’re trying to prove. For the canonical example, let’s say you’re trying to prove age >= n via a government ID. 1. The site does not know who you are. This is the whole point. You generate a mathemati…

Does the "attester" knows who is requesting the information? Can they map which places requests which person?

That depends on the setup but is not related to the ZKP part. “who is requesting the proof that person X has a gov ID where age >= N” is irrelevant in the context of the proof.

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#228
post #34

Earlier quoted context omitted.

We need to stop this helicopter civilization bullshit. We're building 1984 to protect from god knows what imaginary harms. Stop putting plastic wrap around people's freedoms, liberty, and right to privacy.

The harms of smartphones and social media are about as far from imaginary as it could get. The data is screaming at us. We will look back at handing kids phones with instagram like giving kids cigarettes and think wtf were we doing.

You're restating the problem, but the issue is with the proposed solution. Creating a surveillance state in an attempt to improve society is myopic. We know a surveillance apparatus will be abused to oppress people (it's already happening in the US: we have stories all the way back to the NSA/Snowden, but just last week Flock cameras were being abused to stalk ex-girlfriends, the list is endless), so pushing for that particular approach creates a bigger problem (authoritarian surveillance state) than it solves (some kids watching porn and tiktok).

Edgar Friendly got it right, back in 1993:

> See, according to Cocteau's plan, I'm the enemy. Cause I like to think, I like to read. I'm into freedom of speech and freedom of choice. I'm the kind if guy who wants to sit in a greasy spoon and think, "Gee, should I have the T-bone steak or the jumbo rack of barbecued ribs with the side order of gravy fries?" I want high cholesterol. I want to eat bacon, butter and buckets of cheese, okay? I want to smoke a Cuban cigar the size of Cincinnati in a non-smoking section. I wanna run through the streets naked with green Jello all over my body reading Playboy magazine. Why? Because I suddenly might feel the need to. Okay, pal? I've seen the future, you know what it is? It's a 47-year-old virgin sittin' around in his beige pajamas, drinking a banana-broccoli shake singing "I'm an Oscar-Meyer Wiener".

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#229
post #83

Earlier quoted context omitted.

Not that I want my kids looking at porn or violent content, but I’m far more concerned about man-o-sphere influencers than that other stuff.

The "man-o-sphere" is pornographic. Look at the porn-brained Tate brothers for an example. That is their whole ethos and their souls are rotted out by it. Both are based in dehumanization and contempt for women and draws from the well of insecurity, viciousness, and psychological disorder. Both entrench and deepen psychological disorder and immorality. I think the basic error is that we're making a concession to obsc…

So, re-instate the Hays Code, essentially? https://en.wikipedia.org/wiki/Hays_Code

Re: Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance

#230

Earlier quoted context omitted.

Yes, a lot of it involves denigrating women and an entitled and very rigid attitude towards the male place in society (alphas etc). This is incredibly toxic for young men growing up and the women they interact with. Some of the more prominent proponents are actual pimps (the Tate brothers).

[flagged]

I want to be excruciatingly clear: Andrew Tate is a sex trafficker that tells millions of impressionable boys they are owed sex and that women should not be permitted to vote or hold positions of influence, and that they cannot have platonic relationships with women.

The word incel, on the other hand, describes men who are disgustingly behaved and as a result are unable to have romantic relationships.

These are not, in any way, the same thing. This is NOT an example of horseshoe theory.

Post reply on HN