Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
22 points by jana
22 points by jana
Imposing mass surveillance over most communication on the internet just to deny children the ability to socialise online is pretty horrid.
The intention is good. Unfortunately good intentions that make logical sense can still be immoral.
I’m a it though?
Many/most of the people pushing these laws believe that acknowledging the existence of LGBT people is adult only content to “protect” children from.
Also this represents more of a problem with parents refusing to acknowledge sex (and porn, etc) exist and not actually discussing it with their children. Instead they demand others stand in and “protecting” their children from a failure to actually talk about things.
You can't parent just by talking. Sometimes you also have to set and enforce a limit for your kids that they aren't mature enough to set for themselves. We as technologists never gave parents the tools to do that for the Internet, so I don't think it's fair to accuse them of demanding others do their parenting for them.
Then have those discussions and use tools already built into every platform and device specifically for the purpose of limiting access to adult content and similar.
Don’t make raising your kids other people’s job.
use tools already built into every platform and device specifically for the purpose of limiting access to adult content and similar.
That's the problem: no such tools exist for the Internet. That's why there is political will for legislators to build the surveillance infrastructure that enables blunt instruments like age verification laws. If real and effective parental controls existed, there would be less appetite for this.
No generation has ever before faced parenting in the onslaught of information algorithmically designed to grab attention like this one. There's a lot of good things on the internet, but there's a lot of bad things too, and there's a lot of stuff simply not suitable for those who are not mature enough.
Just saying "let parents deal with it on their own" is not going to cut it.
We're in this situation where anti-porn and anti-LGTB groups are driving the conversation because organisations like the EFF and old-school internet activists have nothing to help parents, except appealing to "free speech".
because organisations like the EFF and old-school internet activists have nothing to help parents, except appealing to "free speech".
No? There are so many better options, first and foremost content being tagged with age levels or even content types and parents being able to set programmatic restrictions on what their children can access on their devices. This is already what we do with movies - G, PG, PG-13, and so forth, plus little tags like "Strong Language," "Cartoon Violence," etc.
Unlike age verification, this requires zero surveillance. It does require locking down kids' devices, but that's something most parents can already do!
I only hit those when accessing alchohol related sites and they're literally "click here if you're older than <legal drinking age>".
The EFF is almost pathologically opposed to the idea of government regulation, it would rather have a thousand atomized "voluntary" schemes implemented by an industry that makes its living trying to farm attention than anything approaching effectiveness.
I only hit those when accessing alchohol related sites and they're literally "click here if you're older than <legal drinking age>".
To be clear, I'm describing a standardized scheme enforced by legislation, not an ad-hoc "age gate" like this. In fact I don't think this kind of "age gate" actually fits what I'm describing at all; I would want the page (or specific images on the page, depending on the type of website) to report "I am content suitable for 18+ users only" or "I am content depicting a serious injury" or whatever and for the browser to then check with its (or the operating system's) parental control settings and decide whether to display the image or allow the page to load.
The EFF is almost pathologically opposed to the idea of government regulation
I think it's reasonable to make that criticism of the EFF specifically but it's silly to imagine that nobody has proposed a scheme like the one I'm talking about here; it's brought up constantly in discussions surrounding this topic.
What is meant to happen then?
Please tell me, as there are two options: parents raise their kids, or there is no online privacy, even for people who are talking to their kids or those who don’t even have them.
If choosing not to explain what they’re seeing on the internet, fostering a dialogue where your kids feel comfortable asking you about what they’ve seen, or apparently even going to the simple task of blocking adult and social is too hard then what isn’t?
I've been a big fan of EFF for decades, and joined many of their causes.
However, this article does not feel like an honest analysis. I've written about the pros and cons of the EU approach, and in general I think it is a well-designed one, doing the right things to preserve privacy. So, what does the article say? That v1 has a security hole or a bug. Wow, thank you very much.
This is like saying HTTPS is not a security solution, because we found (and has happened more than once) a bug in library X or browser Y, use HTTP.
ZKP introduce a massive sharing problem as there's no incentive for people to not lend them to children.
They are attached to the device, they are not transferable. But of course, a parent can give their kid their phone, with all their porn history, sexting, their therapy discussions, etc. No technical measure can stop this.
But the "massive problem" is:
So, how is the argument "some kids/teens will use VPN, steal their parents phone, etc" and argument not to take a measure?
I agree that zero-knowledge proofs are the best solution (if any), but the part about device attestation worries me. Users should own their devices, not be at their mercy. This is another service that chips away at the user's power over their own phone. I'd rather have the tokens easily extractable than have them not work in places like GrapheneOS.
One other piece that could perhaps be improved is distribution. Right now, the only risk of identity discovery is when a website and the token granter (presumably the state) collude. But this is not beyond the realm of possibility: there is precedent now overseas for billionnaires getting access to important national registries (see: DOGE). Now, one might argue that a website need not store the tokens, only validate them. But an over-zealous compliance officer will sooner or later elect to log and archive the received proof tokens as a CYA measure.
I wish they'd work more like packs of cigarettes (!) - buy one, present an ID, you get 20 uses of anonymous untracked tokens. Packs do not bear serial numbers, so it is impossible to tell who got which pack even if you paid by card.
Now, tying this to monetary means is probably a bad idea. Still, I would welcome an equivalent that makes it physically impossible to trace back a token to a person even if all parties are untrusted.
Sure, there's number of concerns: https://blog.vrypan.net/2026/07/01/260702-whats-wrong-with-eu-age-verification/
But overall I think EU's on the right path: https://blog.vrypan.net/2026/06/29/260629-whats-wrong-with-eu-age-verification/
I used to think so too, but now I worry that the "zk" part is treated as some extra to be conveniently omitted. Also, I increasingly see how the physical reality in AD2026 can defeat some of these well-intentioned measures.
For example, take website operators. Nobody in their right mind is going to implement a verification gateway or library on their own. Compliance is mostly about shifting responsibility, so inevitably you end up with 2-3 popular providers, much like you have CookieBot and friends for GDPR/ePrivacy compliance. These become the real gatekeepers then, but also, they start keeping records of their own. IP addresses, cookies (!!!), logs, maybe extra stealthy fingerprinting "for fraud detection". The problem shifts elsewhere, and these parties now hold real power. Worse, they are watering holes ripe for attack. This is a model that the various explainers do not even envision, but I am reasonably certain it will end up like this, because we have enough precedent to think so.
Also for the apps. I find it highly likely that, out of 27 member states, at least a few will really screw up the implementation and e.g. forget to disable a debugging Sentry integration that ships all user actions to a third party. An incidental fault for sure, not an inherent one, but real people can suffer because of this. It would be better to exclude such a possibility altogether.
Next, I think such an app reinforces the grip of American corporations on the ordinary lives of Europeans. Also, it ties your own computer use to owning a smartphone. You can't just use the Web from a computer anymore. In this, one becomes disadvantaged relative to people living outside of the EU. It is not an improvement.
Finally, I believe that a state-mandated token issuance poses a future risk in itself in the form of metadata. The fact that somebody had a large number of attestations generated for them makes them a target for investigation and persecution. In Poland, the previous ruling party is known to have deployed Pegasus, an espionage software, against its political opponents. This piece of metadata is like having a target mark painted on your back.
tl;dr this is the best age verification app in existence, it is still not good enough, and now I'm thinking that an app is strictly worse than dumb paper slips with UUIDs printed out and picked up from a "reverse ballot box" at the post office.
I worry that the "zk" part is treated as some extra to be conveniently omitted
Definitely a danger that we should focus our energy on.
Nobody in their right mind is going to implement a verification gateway or library on their own
I think that in zk-proof's case, this is easy, and tbh, much more efficient and demanding demanding than using an external provider, because you just have to validate a cryptographic proof. Not much different than SSL. (I may be wrong, open being corrected)
at least a few will really screw up the [app] implementation
This applies to everything. Banks screw up, browsers screw up, service providers screw up.
such an app reinforces the grip of American corporations
I don't see how. On the contrary, we will probably get rid of all these services that require us to upload our ID/passport.
Also, it ties your own computer use to owning a smartphone.
This is the reality for 99.99% of 2FA users though, isn't it?
The fact that somebody had a large number of attestations generated for them makes them a target for investigation and persecution
I think the proposed design generates the zk proof of the attestation on-device. I.e. you get the state-issued attestation, and your divide generates a new zk-proof whenever it's needed. You could say maybe the device holds a log (that's a danger), but generally, a state is not able to tell if I ever used the attestation or not.
Pegasus
Same in Greece. But tbh, if someone gets control of your phone, accessing the attestation/zk-proof history may not add a lot.
All these are valid concerns, and most of them are related to the implementation. I totally agree that the design offers nothing if the implementation is wrong. This is why we should push for things like verifiable binaries (i.e. anyone should be able to verify that the binary in the App Store is compiled using commit ABC of a publicly available code).
I admire your optimism regarding verification being done by the service itself - that would be best. On the other hand, consider this: a GDPR data processing banner is not hard to implement. Yes, one has to list all the vendors, which can easily be >1000 in a programmatic ad context, but in the end you just format a string (TCF) and save it in a cookie. There is a free library that formats it. Nobody does it on their own because compliance is 99% about shoveling responsibility out of your way and 1% about protecting anyone's rights. Same with auth: companies like Auth0 and Okta thrive (even if many people here, including myself, think that outsourcing authentication is an absolutely terrible idea).
I do hope I am wrong about this, in the end. Instead of Persona assuming one more key function for a very attractive fee.
As for the screw-up aspect, I think we deserve more as a society. Just recently the medical data of 19 million people was leaked in the biggest breach in Polish history. "It happens", people will say. And they would be right. The question on how to prevent errors is therefore inadequate. A better one is this: why does it even exist? Does this have to pass through an app? Does the app have to interactively talk to the browser over Bluetooth? Are we sure we need to include the domain in the challenge that the app sees - is it a good idea to put the Age Verification App as the sole trusted party? Do we have to keep all of our eggs in one basket? With ZK it is supposedly different, but I do not think relying on the correctness of an implementation as the first, and last, resort is the responsible thing to do. Even if the flow is provably correct, all it takes is one compromised library in everyone's favorite kind of attack - supply chain - to potentially gather massive amounts of information.
Governments love centralization. It lets them feel in control. It also makes the blast radius all-encompassing.
Unless you mean that zk hides the identity of the rightful owner, so he has no consequences if they manage to transfer the attestation. If this is what you mean, I hear it.
That is what I mean, and even if they do successfully lock them to the device (doubtful), I'm pretty sure that you'd be able to set up a proxy so that other people can unlock websites.
Also, it isn't really much of a problem that kids can use the internet.
it isn't really much of a problem that kids can use the internet.
I always want to know how old are the kids of the person who makes such a claim. I used to have very different thoughts before I had a kid.
Tbh, I have managed to keep control (not too much, not too little, and yes, I know she has found workarounds), but 99% of her friends parents lack technical knowledge, information about the current state of the web, and parenting skills to do it. And this affects my kid too.
I gotta ask, if you are worried about your kid using the internet, why are you giving your kid access to devices that can access it?
It's not a binary good/bad.
It's like saying, if it's dangerous for a kid to be alone outside, why do you let it out the door? At 5, I don't. At 12 there are places it's ok to be by itself, at 15 it has even more freedom, and so on.
Is it ok that driving, paying for sex, gambling, alcohol have age limits? I think so. Do some kids some times bypass these laws? Sure, and even that's ok to a degree. But it's good there are some lines, even if they are there to be crossed.
Again, it doesn't matter how you prove someone once verified their age, the first step is necessarily compare and store photo to the ID. Otherwise it's no different from issuing drivers licenses (or other age verification) without photos and simply trusting such IDs match the person showing them.
the first step is necessarily compare and store photo to the ID
No, this is wrong.
Nope. Not accepting that answer - explain why I am wrong.
I explained why the photo etc comparison was necessary and I assumed the reason that would need to be recorded was obvious.
If you disagree explain why not, don’t just say No, present an actual argument supporting your position.