Many might’ve seen the Australian ban of social media for <16 y.o with no idea of how to implement it. There have been mentions of “double blind age verification”, but I can’t find any information on it.

Out of curiosity, how would you implement this with privacy in mind if you really had to?

  • chaospatterns@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    22 days ago

    Its possible to implement something that hides your actual age from a website, but the tricky part is hiding what website you’re visiting from an identity provider.

    Let’s walk through a wrong solution to get some fundamentals. If you’re familiar with SSO login, a website makes a request token to login the user and makes claims (these request pieces of user information.) One could simply request “is the user older than 18?” And that hides the actual age and user identity.

    The problem is how do you hide what website you’re going to from the identity provider? In most SSO style logins, you need to know the web page to redirect back to the original site. Thus leaking information about websites you probably don’t want to share.

    The problem with proposals that focus on the crypto is that they actually have to be implemented using today’s browser and HTTP standards to get people to use them.

    • hemko@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      22 days ago

      Could it be maybe a token signed by the verifying party living permanently on your computer (like cookie), and websites can request permission to query it to verify the age?

      • lad@programming.dev
        link
        fedilink
        English
        arrow-up
        3
        ·
        22 days ago

        Since age tends to not decrease, that may make sense: once you reach 18 you get a signed token you can use forever.

        Your token might be used by someone else, though

        • MajorHavoc@programming.dev
          link
          fedilink
          arrow-up
          1
          ·
          22 days ago

          Your token might be used by someone else, though

          Yeah. I feel like that cool bad influence not-actually-my-uncle is gonna publish their porn access token everywhere.

    • JeremyHuntQW12@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      22 days ago

      The problem is how do you hide what website you’re going to from the identity provider?

      Not only don’t you need to, you would really have to know the generator of the token because it needs to verify that you are the user that was issued the token.