Earlier quoted context omitted.
> You don't want these to be replayable (give your JWT to someone else to use) so they need to be bounded in some ways (eg intended website, time, proof it came from you and not someone else). But these are the things that make it non-anonymous, because then instead of one token that says "is over 18" that you get once and keep forever, everyone constantly has to request zillions of tokens. Which opens up a timing at…
The government can already do this with the ISP. I dont think government should be part of the average person's threat model.
This is what VPNs or public libraries are for.
> I dont think government should be part of the average person's threat model.
Tell that to the people in places with governments that are a threat to the average person.
"It can't happen here" is a dangerous hubris.
On top of that, do notice that there is more than one government. What happens when Salt Typhoon comes for this stuff?