Earlier quoted context omitted.
> The government doesn't learn which web sites you visit, and the web sites don't learn anything about you other than you are certified to be age ≥ 16. If the zero-knowledge proof doesn't communicate anything other than the result of an age check, then the trivial exploit is for 1 person to upload an ID to the internet and every kid everywhere to use it. It's not sufficient to check if someone has access to an ID whe…
As I mentioned elsewhere, you’re falling for letting perfect be the enemy of good. The ZKP + phone biometrics only needs to raise the cost of bypass above what adolescents have access to. And no, you can’t just share the same ID because there’s revocation support in the mDL and it’s difficult to extract the raw data once it’s stored on the trusted element. This is very similar to how credit cards on phones work which…
The revocation list means nothing when they can get ahold of someone’s older sibling’s ID and sign up for social media.
Did everyone just forget what it’s like to an ambitious kid who wants to get online?
Do people really think a platform that needs people to jump through these hoops and use this imaginary international ID architecture is feasible?
Does anyone really think that kids won’t just set their location to Estonia and/or use a VPN to circumvent all of this?