Hello,
I was gonna post this on Ask Lemmy, but then I thought maybe Technology would be a better fit for the theme. But then I saw it's mostly news, so I thought perhaps Ask Lemmy would indeed be a better fit. If this is not the case, please point me to the right direction.
As a heads-up, I am not 'Murican, and never been to 'Murica, so keep that in mind.
Seeing the recent news with France trying to age-restrict pornographic material online, I was wondering and have sort of an idea, that I wonder if it is actually doable and actually good.
Hear me out: the gobermint likely already has your data, right? At least stuff like name, date of birth, etc. The gobirment could have a private and secure service, which websites and services could use to confirm certain requirements.
For instance: A website wants to confirm if you're over 18. The website essentially asks the official gob. service, "is this user at least 18 years of age?". The official gob. service essentially has to answer "yes, your requirements are met" or "no, your requirements are not met", without giving away information on a person. The user gets prompted, being told what information is being required and whether they wish to share that. The official service wouldn't know where the request is coming from, but the original website requesting the information generates and shows a temporary code, which is not related to the website at all and is sent to the gob. service, so that the user can confirm it is indeed the website they were using that is requesting this, and not a hijack of some kind. The gob. service, if allowed by the user, sends out this confirmation to the original website, without the gob. service knowing the website and without the website knowing the user's info. The website then knows whether their requirements are met and can then act accordingly, such as by not allowing someone to access adult material if they do not meet the age requirement.
Does this make sense? Is it doable? Could it be a potential private and secure way of confirming user information without either party having access to the other's information? Obviously, the idea could be worked on and polished, but as a starting point.
Edit: so, what I'm gathering from comments here:
- Som'o'y'all didn't get it (no, you don't got to log in to your porn tube of choice with an official gob. account)
- This cannot be done
- This could be done
- This is already a thing being worked on
I think you'll need to generate a OTP type thing from a government site that's a message with a timestamp and maybe the code provided (and chosen by) the website signed by that site's private key, then have the 18+ website check that it's signed by the government.
Basically, the digital equivalent of your teacher giving you a letter/consent form to bring home for mummy to sign and then return to the school.
Possibly you could have a fingerprint that goes on it that only the government could recognise if the website hands it over to them (likely under court order) if you are concerned about fraud/people using other people's accounts.