Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An id card is a bearer token.

You can get an anonymous, cryptographically signed, certified legal bearer token confirming your age only, or identity or whatever by a centralized service, be it government or high trust private organizations who need to verify your identity anyway like banks. With some smarts you can probably make such a token yourself so the root bearer token issuer doesn’t have the one you use to browse pornhub.



Which inevitably can be deanonymized after a simple law change, mandating the required data to be reported.


https://datatracker.ietf.org/wg/privacypass/about/

Perhaps a system like Privacy Pass would be ideal. Where a verifier generates a verified client a number of redeemable signed tokens for a session, but when presented by a client, the site doesn't know who that token was issued to, but they know they authenticated this person and can verify they made the token. Therefore they get access.


You're looking for a technical solution to a political problem. This tech is useless the second a law is passed that identities have to be logged. It's also useless if implementers decide to collect identifying information without telling you.


That also weakens circumventability. What's stopping me to sell my signed tokens to the highest bidder on ebay?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: