Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • When a user reuses a previously saved government ID is that ID decrypted and sent in plaintext to your service? (Ie. does your service see the ID in plaintext every time a user uses the service?)

    Do you use zero-knowledge proofs in any way?

  • This wouldn't pass muster for the "age verification laws" that various governments are implementing or have planned. Even if the laws currently on the books or being proposed do not have the requirements, "KYC to touch a computer or communicate over the internet" is the goal. People are crying out for their children to be kept safe online, and the solution the government knows is a full auditable trail of who communicated what to whom when. This also nicely solves the problem of "anyone can set up a new online service", allowing the big players to entrench themselves...
  • These solutions will never be viable, and I'll explain why. Fundamentally, there's three sets of the population:

    1) Those who are clamoring for age verification (generally on sites they never interact with themselves.)

    2) People arguing fiercely against age verification and won't engage with any site who uses it

    3) Most significantly, the large majority of people in the middle who can't be bothered to do AV and will just use another overseas website instead.

    Even if the privacy can be solved (and I don't believe it can as someone fundamentally unwilling to upload my ID even once), that balance is basically the problem with trying to outsource the work to people who don't want to do it. We can already see that even privacy preserving solutions will not be used by adult site visitors in multiple adult site attempts to roll it out. The ONLY viable solution is parental filters on device. Anything that pushes the work to people who don't want it fails because the sites will just move overseas instead of losing the vast majority of their actual users. Or they roll it out and the traffic moves overseas, like data analysis has shown happened in UK.

    You just can't solve the problem by pushing the work onto everyone instead of tackling it at its source. Rather than try to lock down the entire Internet, which will never happen, lock down child devices.

  • > When identity documents are uploaded, they are encrypted using a master encryption key derived from the user’s passkey during authentication.

    ONE still sees identity documents in the clear the first time when it verifies them, right? Otherwise we could upload fakes.

    Also I'm not familiar with Oauth 2.0, but doesn't ONE know the client and relying party on each verification transaction? So ONE could theoretically store records of who accessed which website, perhaps by mistaken logging configuration or because they were coerced by law enforcement.

    Anyway I appreciate the consideration given to privacy.

  • I wrote up more of the thinking behind this here for those interested:

    https://loginwithone.com/blog/the-internet-should-be-more-li...

  • There are (at least) two problems to solve. The first is to anonymously verify properties about the user (e.g. age) and the second is to only allow the legitimate person verify themself.

    An national electronic id would provide users with the possibility to verify their age, that they are a physical person and so on, but in the basic case it gives their identity away to any system they use. Letting someone else use your id-card is in many countries illegal and comes with possible negative consequences. Share access to my e-id would allow them to access my bank account, take loans in my name, file for tax returns and a whole bunch of other stuff. So: e-id is not anonymous but usually kept from unauthorized use.

    One solves the anonymity part. Is the document in the encrypted blob accessible by the user? Can my identity be shared with websites? Basically: what stops someone from sharing their One passkey? What stops me from letting my AI agents use it, share it with my younger cousin or sell it online?

  • "One stores ciphertext: encrypted blobs created with a key held by the user. Never the underlying identity data. This includes government ID and selfie data, as well as the verified email associated with the account. "

    Why does it need to store even encrypted data after the result is +18, for example? Does ONE need to keep validating against the same documents every time?

    by thcr

Explore Birbla archives