Remix.run Logo
packetlost 5 days ago

I feel like you could, theoretically, have a service that has an ID (as drivers license ID), perhaps operated by your government, that has an API and a notion of an ephemeral identifier that can be used to provide a digital attestation of some property without exposing that property or the exact identity of the person. It would require that the attestation system is trusted by all parties though, which is I think the core problem.

brian-armstrong 5 days ago | parent | next [-]

Wouldn't this require the API provider to know that tbe citizen is connecting to the app? Grindr users might be squeamish about letting the current US admin know about that.

mschuster91 5 days ago | parent | next [-]

ICAO compliant ID cards (aka passports) and many national ID cards already are smartcards with powerful crypto processors.

Hand out certificates to porn, gambling or whatever sites, that allow requesting the age of a person from the ID card, have the user touch their ID card with their phone to sign a challenge with its key (and certificate signed by the government), that's it.

Government doesn't know what porn site you visited, and porn site only gets the age.

packetlost 5 days ago | parent | prev [-]

Not necessarily, you can define the protocol such that it's all done with opaque IDs instead of identifying info.

red_trumpet 5 days ago | parent | prev [-]

This is not only theoretical, the German ID card ("elektronischer Personalausweis") can do exactly this.