Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't think that the digital ID provider is keeping logs of which sites requested to verify which users? Even government websites are not exactly known for their high security.




The digital ID provider is only involved in issuing the ID to you. When you use that ID to verify age to a site the only communication is between your phone and the site. The ID provider has no idea when you use the ID, how often you use the ID, or where you use the ID.

Briefly, when the ID provider issues the ID it gets cryptographically bound to your phone. When you use the ID to prove something to a site (age, citizenship, etc) the is done by using a zero-knowledge proof based protocol that allows your phone to prove to the site (1) that you have an ID issued by your ID provider, (2) that ID is bound to your phone, (3) the phone is unlocked, and (4) the thing you are claiming (age, citizenship, etc) matches what the ID says. This protocol does not convey any other information from or about your ID to the site.


This doesn't work because you can't prove the origin of a single bit of data without the associated identity and the origin of the data can only be verified by matching the biometric image on the ID against your real face with a camera.

Otherwise a single person could donate their ID card and let everyone else authenticate with it.

Now you might counter and say it would be enough to give each card a sequential number independent of the person's identity, but then you run into another problem. Each service might accept each card only once, but there are many services out there, so having a few thousand donations could be enough to cover exactly the niche sites that you don't want kids to see.

There is no way to implement this without a complete authoritarian lockdown of everything. There will always be people slipping past the cracks. This means all this will ever amount to is harm reduction, but nobody is selling it on that platform. Nobody is saying that they are okay with imperfect compromises.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: