[Cryptography] Anonymous age verification
John Levine
johnl at iecc.com
Thu Jul 16 20:56:09 EDT 2026
It appears that Ron Garret <ron at flownet.com> said:
>In practice, however, there are myriad problems. The most obvious one is that there is nothing to stop a legal adult from giving
>sub-credentials to their friends, or, for the more enterprising, selling sub-credentials to strangers.
The obvious approach is to tie the credential to a device, most likely a mobile phone.
That doesn't completely fix the problem but it makes it a lot harder to defeat, just like
the security devices in passports and drivers' licenses. They don't make them impossible
to forge, but they make it a lot harder.
As I think other people have said, for this purpose a scheme doesn't have to be perfect to
be useful. As always I can think of other problems, like how you tie the age credential to
the phone in a way that doesn't leak all of the other user's information, but again that
seems like a problem that can be mostly if not perfectly solved.
R's,
John
More information about the cryptography
mailing list