> "and having offshore porn sites or any other third parties collect IDs from adults and becoming a repository of potential blackmail material comes with its own risks [...] A more technically sound approach would be content controls directly implemented on the devices parents chose to give their children" said the company's (Proton's) spokesperson While I agree with their second point, the first argument sounds a bi…
> “double-anonymity” or "double-blind" protocol: the site never sees the user’s identity, the verifier never learns which site is being visited, and only a yes/no “18+” token is exchanged. Isn't this an actually reasonable solution? I assumed age verification was supposed to be done by the site itself, and therefore it was considered a very bad idea. But this... what's the problem with this method?
You're just hoping that there's never a leak of any UUID(s) that could be used to correlate things. The ad-tech industry has pioneered de-anonymization tech and they're very, very good at it.
Tangential question: if the principal is divorced from the "is not a minor" signal, what prevents a thrifty youth from just buying/stealing somebody's token?