Of course they aren’t. They’re just the least bad implementation of a terrible idea. Which seems to be more bad than I initially thought.
Great article, as usual with EFF, but now I’ll be even more depressed about the Internet’s future.
No ASL allowed, did we suddenly forget!? I don’t care how good the implementation is of a shitty idea that goes against everything we learned about the Internet.
The mechanisms underlying ZKPs pose an existential threat to everyone’s digital rights, not just kids. The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user’s access to a service, essentially removing that person’s access to the internet entirely. Without oversight of who has authority to implement and operate these systems, this approach centralizes critical internet infrastructure in the hands of very few actors.
But that’s not how EU age verification actually works, no ?
You verify once and then can use that token offline, and there’s no recontacting the issuer once you log in / sign up (at least supposedly).
Kinda confused me at the start, I guess they’re strawmanning here a bit of what COULD happen.




