132
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 10 Sep 2026
132 points (98.5% liked)
Privacy
10726 readers
124 users here now
A community for Lemmy users interested in privacy
Rules:
- Be civil
- No spam posting
- Keep posts on-topic
- No trolling
founded 3 years ago
MODERATORS
The EU is building the EUDI wallet (or rather requiring each member state to provide a solution) and it will be possible to prove your age with that without disclosing details about your identity. And it's even possible to do this on your device, so the state won't know who you're proving your age to. Just saying that there are ways to do it right. It's just a matter of whether everybody wants that.
No, there is no way to do "censoring access to information for young people" right. That remains an entirely illegitimate goal no matter which mechanisms you invent for doing it in a privacy preserving manner.
Using the neutral term "information" here is doing a lot of heavy lifting for your argument.
Nobody is banning the youth from accessing wikipedia or a library or minecraft.
And if a young person really wants to watch at porn, torrenting/piracy will always be there without age verification.
Speaking of minecraft and circumvention, do you remember the uncensored library map? https://www.techdirt.com/2020/03/19/routing-around-damage-censored-reporting-hosted-custom-built-minecraft-library/
I bet someone inclined to do so could host a pornhub mirror/proxy inside of a modded minecraft map.
But also, if the parents decide that it's part of growing up they can just give their kids access to porn.
Oh uuuh I mean, not porn, iNfOrMaTiOn.
Wikipedia has pornographic images and videos in it (certainly in its media archive, Wikimedia Commons, and some of them are embedded in articles).
Library: ??? Are we still talking about the Internet?
Yes. Giving kids access to the open Internet is giving them access to a repository of nearly all human knowledge and endeavors, including (but not limited to) porn. If parents believe their child isn't yet developmentally ready to be exposed to all human knowledge and endeavors, they shouldn't be giving that child (unsupervised) access to a worldwide information system whose entire purpose is to provide access to exactly that.
You keep speaking in extremes and absolutes. There is also pornographic content walking outside on the street in the city if you so wish to classify it (and some people certainly do to they point where they get turned on by seing a bare ankle).
Certainly the pictures and videos on wikipedia which you chose to consider pornographic rather than neutrally informative have a different set of qualities then what you would find in the extreme sections of porn-serving websites.
There is a middle ground. You can give partial access. And age verification is one more tool for that (we already have parental controls for routers and mobile internet simcards and smart devices)
I don't like nor want age verification btw. I just don't agree with your arguments against it, because I find them weak.
Look into the Wikimedia Commons category "pornographic videos" and you'll see what I'm talking about. Not linking to it because I'm not sure I'm allowed to do that here.
Hence why I wrote specifically about the open Internet. You are right: there are ways to give people access to only a selected part of the Internet. If parents decide to do that, fine; doesn't have to concern any website operators, or any adults.
Like I said, I agree. But your initial argument is no good. You toss everything into one box to make your claim appear stronger but in doing so you actually make it dismissable. Stay differentiated.
YOU are the one that immediately jumped to porn, shithead. You DON'T get to decide on talking about extremes and absolutes.
I didn't jump to it. It's the primary reason for age verification.
Calling it "information" to avoid talking about it is intellectually disingenuous.
Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
Personally I'm optimistic that tech like this can be used in positive ways, but imo they should be developed transparently (open source) and decentralized.
How could the issuer track when a credential is used? Isn't the whole point that the issuer isn't needed for verification of the ZKP?
Because the credential is unique. Imagine you submit it every time you log into Google, Facebook, and Youtube. They could all collude and see that the same age verification token was used and link the accounts.
They are use once tokens, you get given like 50 or 100 when issued. There's no way to link them
If they are use once tokens then you need to get more. If implemented badly, they could be asking for a new one every time, and now the issuer knows whenever you are using them. I'm not sure exactly what implementstion flaws The EFF article was talking about but they have links if you want to learn more.
Edit: also, now that I think of it, if it's single use, then they need to be invalidated every time they are used. So this probably also notifies the issuer every time a token is used, and which token it was. There are probably ways to do this privately but it is a tricky problem, and something the government probably won't get right the first time, which is the main issue that the EFF is talking about.
The single use part is just for your privacy, they don't have to be invalidated. You could just have them last a week or
<time interval>on issueYou're talking about potential implementations. EFF is talking about issues in current implementation. As I said in my very first comment, I'm sure it can be done properly. The EFF is worried that if the current implementation is rolled out now, the system will stay unfixed for years and make privacy even worse.
But anyways, since you seem knowledgeable about the EUDI implementation and I'm too lazy to look it up, do you know if the current implementation allows a website to collude with the issuer to get the identity of a user?
My reference point is cloudflare's research on zero knowledge proofs used to issue anonymous tokens to bypass (pre-complete) captcha checkpoints.
Neither website nor issuer (nor the combination) can determine the identity of a user from the token (hence zero knowledge), but other techniques entirely unrelated to the cryptography can identify a user. For example network or browser metadata or traditional browser fingerprinting.
I see so it seems like we were talking past each other. I'm aware of Cloudflare's token system. As well as other systems like GNU Taler and Monero. So clearly privacy preserving systems can be built. But I also trust the EFF, and if they say the current system has major flaws I'm inclined to believe them
The age verification system can't be zero knowledge if they know what your token is, and can track it. Seems a bit funky
As you said, there's still metadata. For example, if they requested a new token every time you used one. Technically the token itself is still zero knowledge, but now the issuer knows when you use it.
In that argument the issuer is a private entity. In my argument the issuer is my country itself and they're not involved in the proof, because it happens on my device. The EUDI wallet, at least in theory, will be trusted, because it is signed by an EU member state. And it runs on my device, so the state doesn't know what I use it for. Just like a physical ID.
Ok so you clearly didn't read the article because it calls out EUDI explicitly:
the country is not trustworthy
Nope, it won't be anonymous.
Look, any kind of digital age verification must be connected in some way to an actual identity.
If you are running a community operating under EU laws to require age verification, then a simple true/false statement won't cut it.
You will be required to log a personal ID number of the user, signed by the digital wallet issuer, that is the only way to guarantee that a specific person was verified to be of age.
You as an admin of the community might not know the identity of the users, but the government can tie the account back to you.
The EUDI wallet is advertising that it can prove your ID on device and just send a "is over 18" confirmation. So at least in theory, the wallet should provide verification without giving your ID to whatever service you want to use. I do doubt however, that ot will work that smoothly and securely in practice
ADVERTISING. Don't treat marketing as truth
No, there's no theory here. Just lies.
As Louis Rossmann once said: Dont accept the premise of assholes. Don't repeat their lies for them.
Good thing their app requires Google Services making lineageOS and eOS unable to run it (no desktop app either)
Storing identification information on an internet-connected system will never be safe for the people whose information is collected there. Such databases are high-value targets. They always get attacked, and the information stolen. This cannot be done safely.