Age verification
(laws and regulations requiring platforms and websites to assure or estimate that a user seeking to use an online service is of a certain age) is everywhere. At the time of writing, about
half the states
in the US have some internet age verification law in place, and dangerous proposals, from the
KIDS Act
to the
Kids Online Safety Act (KOSA),
have been advancing at the federal level. European Union member states are moving toward having age verification
in a centralized app
by the end of this year.
Australia famously now has one extremely broad restriction in place
.
Most age verification laws
tend to fail
at
their primary goal
of barring kids from being online or from entering only specially designated zones, not to mention they pose a significant threat to everyone’s privacy. Some proponents of these age-based internet restrictions think they've found the silver bullet: Zero-Knowledge Proofs (ZKPs).
We wrote about ZKP’s
when they were first rolled out in the age verification context last year. However, more recent examples show our concerns weren’t just conjecture; ZKP-focused AV schemes are
gameable
, hackable, and not the cure-all some may claim.
ZKPs in Age Verification Would Only Centralize Power and Create More Harms
Before we jump into how these systems work, it must be said: creating a single point of failure for internet access contradicts the very idea of a free and open internet.
The mechanisms underlying ZKPs pose an existential threat to everyone’s digital rights, not just kids. The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user's access to a serv
… [more]