• Ferk@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    1 day ago

    That prevents the site from knowing your identity, but I’m not convinced it prevents the government from knowing you visit the site. The government could keep track of which document corresponds to which individual whenever they issue / sign it.

    So if the government mandated that each signed proof of “age>18” was stored by the service and mapped to each account (to validate their proof), then the government could request the service to provide them copy of the proof and then cross-check from their end which particular individual is linked to it.

    • M1k3y@discuss.tchncs.de
      link
      fedilink
      arrow-up
      1
      ·
      5 hours ago

      The reason why it works is a bit complicated, but basically the trick is that the signatures are not immutable. Given a valid signature, it is possible to create a new valid signature over the same content that is not linkable to the original one. This means that it is still possible to derive, what authority signed the document, but the authority cannot know in which transaction it has signed that specific document.

      • Ferk@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        2 hours ago

        If you have no way to link the signature to the original document, then how do you validate that the signature is coming from a document without repetition / abuse?

        How do you ensure there aren’t hundreds of signatures used for different accounts all done by the same stolen eID that might be circulating online without the government realizing it?

        Can the government revoke the credentials of a specific individual? …because if they can’t then that looks like a big gap that could create a market of stolen eIDs (or reusing eIDs from the deceased) …and if they can, what stops the government from creating a simulation in which they revoke one specific individual and then check what signatures end up being revoked to identify which ones belong to that person? The government can mandate the services to provide them all data they have so they can analyze the data as if they were Issuer, Registry and Verifier, all in one, without separation of powers.