this post was submitted on 30 Nov 2024
127 points (99.2% liked)

Programming

27131 readers
353 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 3 years ago
MODERATORS
 

Many might've seen the Australian ban of social media for <16 y.o with no idea of how to implement it. There have been mentions of "double blind age verification", but I can't find any information on it.

Out of curiosity, how would you implement this with privacy in mind if you really had to?

you are viewing a single comment's thread
view the rest of the comments
[–] letsgo@lemm.ee 32 points 2 years ago (2 children)

Not a cryptographic expert by any means but maybe something like this would work. This'd be implemented in common places people shop: supermarkets for instance. You'd go up to customer service and show your ID for visual confirmation only; no records can be created. In return the service rep would give you a list of randomised GUIDs against which the only permissible record can be "has been taken". Each time you need to prove your age you'd feed in one of those GUIDs.

[–] nutsack@lemmy.world 7 points 2 years ago (1 children)

this is an actual answer which is therefore interesting

[–] litchralee@sh.itjust.works 15 points 2 years ago* (last edited 2 years ago) (1 children)

Sadly, this type of scheme suffers from: 1) repudiation, and 2) transferability. An ideal system would be non-repudiable, meaning that when a GUID is used, it is unmistakably an action that could only be undertaken by the age-verified person. But a GUID cannot guarantee that, since it's easy enough for an adult to start selling their valid GUIDs online to the highest bidder en-masse. And being a simple string, it can easily and confidentially be transferred to the buyer, so that no one but those two would know that the transaction actually took place, or which GUID was passed along.

As a general rule, when complex questions arise which might possibly be solved by encryption, it's fairly safe to assume that expert cryptographers have already looked at the problem and that no easy or obvious solution exists. That's not to say that cryptographers must never be questioned, but that the field is complicated enough that incomplete answers abound.

IMO, the other comments have it right: there does not exist a general solution to validate age without also compromising anonymity or revealing one's identity to someone. And that alone is already a privacy compromise.

[–] LordCrom@lemmy.world 1 points 2 years ago

To be certain the list isn't being handed out willy nilly, your id must be scanned, that will be kept for auditing purposes. If only 10 guids can be given at a time, this is the only way, plus it identifies ids used too often.

And I can guarantee any powers that bee will turn this into a service like stupid id.me where you create an account for guid access