Comment on Online age-verification tools spread across U.S. for child safety, but adults are being surveilled

<- View Parent
Kraiden@piefed.social ⁨20⁩ ⁨hours⁩ ago

verification necessarily ties your device to your personal identity

needs to be an identifier associated with every device/account

I think you’ve misunderstood. Neither of these statements is true

If there were any possibility that a state actor had interest in identifying my personal identity of this account, and there was a record that pointed to my name, SSN, or other unique personal identifiers

That’s the whole point. This isn’t possible. There are NO identifiers ANYWHERE that link your account to your real world credentials.

if it’s being verified by a state authority at all

It’s not. At least not in the way you’re thinking. You are issued a file, like you are issued an id. This could be done from any device anywhere, and could theoretically be copied and moved around to other devices. This file is cryptographically SIGNED by the state.

Meta then send you a request with their own cert.

The third party then generates a 3rd cert that JUST verifies that you are of age, and contains NO other PII. It uses a combination of signatures from the request and your credentials file to generate this.

The result is that Meta can verify that this new cert was generated in response to their request, that it was based off of an authentic state credentials file, and that the user is of age. That’s it. Not the exact date of birth, no names, addressses, ssns or anything. JUST “user is >16.” There are no identifiers, and no way to tie it back to you IRL.

The state get absolutely no indication that any of this has gone down at all. The 3rd cert is verified off of a universal public key

source
Sort:hotnewtop