The alternative is do it offline.
Plenty of European countries have an eID CAs and it works fine. The PKI part is a solved problem.
Doesn't even need ZKP, the CA can just issue an attestation.
https://www.fourmilab.ch/documents/digital-imprimatur/#SI_an...
Most operating systems and browsers come with a sync mechanism that many people default to, but it's no more than that: the default.
As for account recovery, most websites have a way to recover your account when you lose your password, there's no reason why that wouldn't work for passkeys. Every website with passkey access I've used so far makes passkeys optional and forces you to set a password already. If they switch their default to passkeys and add a password as an optional step, nothing would change.
It's not all sunshine and roses, though. Despite having Bitwarden set as the only passkey provider in my Android setup, the phone persistently only offers me Google. Which is empty, because as I said, I won't use one tied to things I can't control. Works great on desktops, though.
Passkeys can theoretically require you to be on hardware, I haven't found anything yet that requires that.
[0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
But it’s also the kind of story that won’t stay down, and will definitely be back.
It appears as if there are folks here that don’t want to talk about this.
But it's still the type of story that should have had a much longer tenure, especially as it was Krebs.
I am now thinking that the access may have been through a backdoor. It certainly seems to have operated like a direct intravenous link.
BTW: Thanks for this link: https://securitywall.co/tools/ipa-analyzer
Looks interesting.
‘Just make the encryption secure and so we can read it’
‘Just check everyone’s id but make it totally secure’
The problem is that it is really, really hard to make something secure even if you try and follow all the best-practices you know.
I guess the awkward bit is marketing everything as certificate this, accreditation that and overselling how secure it is although I don't really know how else you would word it, "as secure as we know how"?
It's been released and in production since summer. Since then, several social networks have apparently started A/B testing age verification for their EU users, but how many of them actually integrate with the anonymous solution that is now available and in production? To my knowledge: 0. They all use Persona.
This highlights one of my main criticisms of EU's naive approach to regulation of tech companies. They fail to realize that any regulation that they impose will be complied with in the most malicious way possible, which is how we got cookie banners with dark patterns instead of a simple HTTP header saying no thanks to cookies.
Note that’s this is not here some rant against any governmental power, just that in context, large private group use them as puppets and shrink their budget which of course impact quality of deliveries (not shaming the people who do the hard job without the relevant means). And while more distributed governmental topologies would have their own caveats, at least it would less likely offer opportunities for single point of failure.
During the totalitarian communist rule in Czechoslovakia, the state would regularly interfere with passports of people considered not loyal enough - withholding them outright or inventing extra paperwork that was necessary for the border police to let you out of the country. They also controlled all supply of foreign currency, both in an out.
Then if someone was actually allowed to travel outside the country but failed to return, their family and relatives would be punished, including demotion at work & prohibition of higher education.
So if your government goes bad, this is what will happen - the form of the ID takes at that point does not make much difference.
If Apple (or another large international company) suffers from decreasing margins, gets a new CEO and decides to turn the data it sits on into money there is absolutely nothing you can do, and you might in fact still stay a "forced" customer because of network effects (=> just consider whatsapp being an important communication channel in many places worldwide).
I think this attitude in general is often harmful; if your government sucks, fix the government instead of making yourself dependent on some quasi-monopolist private company.
Indirectly only. This is typically also always too late; instead of doing "the right thing" in the first place, companies are disincentivized by regulation from doing "bad things" again.
Regulations are like scar tissue, they don't help against getting burnt in the first place.
Preemptive regulation typically sucks, and is admittedly extremely difficult to get right; most governments don't even bother trying.
Corporation know this and exploit it ruthlessly-- there are almost never consequences as long as they keep to the letter of the law, even when acting with intent, against better knowledge and causing astronomical damage to society (just consider the whole leaded gas disaster for an extremely clear example).
If anyone has to have this type of control, better it be a local national government that you can in at least some small way influence.
For those unfamiliar, you are, of course, allowed to peacefully protest in support of Palestine in the UK.
Palestine Action is a specific group that was controversially labelled as a terrorist group after they broke onto a runway and spray painted military planes.
The .name thread that is on the front page right now mentions specifically registering a domain that wasn’t managed by Verisign because they aren’t trustworthy. But now Verisign does own it and Verisign is doing Verisign things.
You trust Apple today. Will you trust them tomorrow? Will you trust whoever buys them, or at least their identity verification business?
What's going on in France?
The principle reason why the Netherlands joined the EU was to sabotage the French-German alliance- all the alarm bells went off in the 1950s.
These are hardly military grade networks, as long as the driver licence scans make it to the database and can be used to identify and recover damages from accident or theft it's unlikely anybody has cared much past that functionality.
I’ve often thought that replacing the US social security number with a more robust root key makes for a fun thought experiment. Hard to imagine how such a system could securely serve so many people but passports with embedded chips seem to be doing okay.
Hackers Had a Live Feed of Every ID Verification Company Scanned
(Huh? How do you scan a company?)
The original title is easier to parse:
Hackers Had A Live Feed Of Every ID This Verification Company Scanned
That's a sarcastic joke. It's how governments demand private companies react, but ...
Yeah just like how the multiple breaches and utter negligence from the incumbent credit bureaus killed the credit file managed by private companies.
I dunno if I agree but I think that's the thrust of it.
https://www.google.com/search?client=firefox-b-d&q=MEPS+assh...
But more serious and non joking answer, the new thing from the "department of war" is testosterone level lab exams for existing servicemembers.
https://news.google.com/search?q=US%20military%20testosteron...
https://www.google.com/search?num=10&client=firefox-b-d&hs=Y...
Using ZKP as the EU proposes is the only way to prevent this data being leaked to unreliable third parties and leaves the knowledge with the institution it derives from in the first place.
I don't know why HN rails against it constantly, it is the obvious technical and organizational solution to this issue.
Theres no avoiding this, structurally. So the best thing you can do is not to introduce any additional points of failure.
There are zero knowledge proofs
There's a EU initiative https://digital-strategy.ec.europa.eu/en/news/commission-mak.... The direction is generally good, but I'm not very positive about the implementation (as with everything comes from the govs).
Imagine your idealized ZK address verification scheme. It would go something like: I show up at a website, it sends me some challenge, I send back a signature of the challenge that could only be made by someone with an of-age ID, but without specifying who. Everyone is happy.
Now little Johnny borrows my ID, and uses it to setup some oracle that provides ID validation for every kid and bot in the country. Woops.
To stop that you must compromise the idealized zero knowledge properties of the scheme, and in doing so you create the potential for harm/risk for everyone.
Sure, it's better than sending an ID card live feed to the dark web, but the risks of ID card theft are at least somewhat easy to understand.
Some of the threats to human rights don't even require the departure from the 'idealized' model-- as even the idealized model requires an ID issuer to issue the of-age person an ID. And so if the ID ZKP is widely required then the issuer can unperson you by simply declining to issue you an ID.