Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The way identity wallets work:

The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined with the public key with the government private key. The government certificate containing the public key is, well, public.

One of the attributes is ‘over_18’ (In the EU eID scheme countries can add other over_XX attributes if they want, but over_18 is mandatory).

When a website wants to requests attributes, in this case the over_18 attribute, they send a request to the user’s wallet app, including a challenge. The wallet sends back a package including the government-signed attribute, which contains the device public key and the over_18 attribute plus a response to the challenge (proving the credential didn’t get transferred).

The website only sees the ‘over_18’ attribute, which is backed by the government signature. They don’t see any other attributes (the wallet app shows in advance which attributes you are sharing). The government never sees which website wants to know if you’re 18+.

Of course this is all a bit simplified, check OIDC4VCI and OIDC4VP for details.

The only real issue is the wallet app and device binding. Because a compromised device could allow credentials to be transferred some form of attestation of device and wallet app is required. In practice this means no rooted/jailbroken phones.



> The website only sees the ‘over_18’ attribute, which is backed by the government signature

Not true. The device's public key is also sent, which functions as a stable device identifier.

We've spent years trying to get away from stable tracking IDs and fingerprinting. Returning to a system where devices are sending a stable ID to a website to prove ownership is a step backward.

There are proposed mitigations like issuing multiple sets of credentials or rotating them, but we're not going to get an infinite number of keypairs for every website or session in the secure enclave in practice.

Another reason why these proposals aren't getting much uptake is that they aren't addressing what the lawmakers are pursuing: They don't want anonymous authorization tied to the device. They want IDs tied to accounts and a way to discourage people from sharing IDs. In the anonymous systems it only takes one person a few minutes to put an over-18 identity into a device and there's no way to determine if someone is abusing the system by stealing IDs or if someone's 18 year old brother is setting up all of their younger brothers' phones for $5 each.

The situation gets stickier when you acknowledge that it's not possible to limit all of these websites to only mobile phone devices with secure enclaves that are not jailbroken. Once you open a door to desktop devices and other OSes accessing these sites, you open the door to replaying and proxying attacks, where someone will produce those `over_18` attestations on-demand for you, possibly for a minimal price. This brings us back to the public stable identifier to discourage fraud, which means governments won't be happy to issue as many keypairs as we want, which means we're back to semi-stable fingerprints.


> Not true. The device's public key is also sent, which functions as a stable device identifier.

This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted. The wallet will automatically request new credentials in batches when they run out. The old key-pairs are deleted along with the credential so you don’t run out of space in the secure enclave.

> Another reason why these proposals aren't getting much uptake

I’m not sure what you mean by not much uptake, EU countries are required to issue and accept them for official business by the end of 2026


> This is covered by allowing for single-use credentials.

They said There are proposed mitigations like issuing multiple sets of credentials or rotating them, but we're not going to get an infinite number of keypairs for every website or session in the secure enclave in practice.

> Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs.

The comments you replied to omitted mass surveillance. But the article and 1st comment included it. The government would know what wallet requested each single use identifier.


> The government would know what wallet requested each single use identifier

Which only means that the government knows how many tokens each citizen consumes on average. They don't know where each identifier was used nor the exact timestamp unless each website communicates this to the government, and such a backchannel does not exist in the spec.


You did not know governments demanded records? Or infiltrated networks?

And governments investigated high electricity users as suspected marijuana growers. Would governments ignore high identifier use?


Can you make an actual argument rather than spouting insinuations? It's rather tiresome to have to construct my own straw man from your drivel.


> This is covered by allowing for single-use credentials. IIRC the EU personal IDs will use this. Basically, the wallet requests a batch of single-use eIDs that all use different device key-pairs. Each credential is only used for one request and then deleted.

But this then means that the issuers and the verifiers can trivially collude to deanonymize holders/users.


The government will, of course, log all issued public keys and who they belong to.


> The wallet will automatically request new credentials in batches when they run out.

Is that an ongoing cost that I’ll pay for via taxes? It doesn’t matter how anonymized all the schemes are. The government needs to give permission by signing attributes. It will be abused to gate everything we can do.

I wouldn’t be surprised if everything is gated behind attestation fairly quickly. Then our “secure” devices will attest against us if we do anything that isn’t a government approved activity.

Hopefully they never manage to hijack our network protocols. Imagine something like SNI, but it’s an attestation that traffic originated from a secure device that’ll participate in the scheme you described. Then your ISP can drop non-compliant traffic and you can only engage in government approved activity.

The answer to these proposals should be “no”.


Whatever the system is taxes will pay for it and the inherent cost will not be very high, but it'll be contracted to a greedy money-wasting government contracting firm like Oracle, as always happens.


There are schemes where you don't need key pairs for each user (assuming the government has some way of authenticating users). Private State Tokens use blinded tokens for this.

It doesn't prevent tokens from being stolen or sold, but the token issuer only accepts each token once and can limit the rate that tokens are issued and control how fast they expire, giving decent control over how practical using stolen or sold tokens are.


And giving the token issuer the ability to cutoff user access unilaterally.

There is verification. And then there is continuous control. The later is even more problematic.


> In practice this means no rooted/jailbroken phones.

Personally - this is less acceptable to me than just having the site collect my image/id.

I'd support just putting the id in a dedicated device (ex - gov issues smart key) or just accepting that sometimes people will share id info (just like... physical ids).

It doesn't even close all the doors to transferring ids - since I can still just hand someone a phone (just like... physical ids).


If you use physical ids to verify your identity, they normally verify that your face matches the image on the id, no? That’s not possible for web id.


Doppelgängers Don’t Just Look Alike—They Also Share DNA

https://www.smithsonianmag.com/smart-news/doppelgangers-dont...


Yeah, but being able to share Id with someone who happens to look eerily like you is different from just handing people your ID and they are able to use it like it was implied. That’s not how IDs are used.


My experience has been that absolutely no one cares, as long as they could be construed to be "somewhat similar".

Ex - People change hair color, lose a boat load of weight, wear eye-color changing contacts, drastically change hair styles (facial and normal) etc...

No one bats an eye at an ID that "only sorta vaguely resembles you" outside of a very limited subset of places (the only one I can actually think of is Customs while traveling).

---

So my take is that as long as the gender appears similar and the ethnicity seems "close enough"... the store is still going to sell you alcohol, the bar is going to let you in, and the movie theater is going to sell you tickets.


If you are referring to EUID (not fully sure as you said EU eID, i dont know if you are referring the estonia of eID like system)

I have to mention that EUID is not private, since there's "provider" element which informs website if you are 18 or not. The flow is:

1) You scan QR code 2) Your EUDI wallet does verification, informs provider to tell you are 18+ 3) Provider informs website you are 18+

The EUID draft doesnt mention tech like ohttp for anonymizing requests. So there's risk of provider keeping track of who you are. So while everybody claims its fully anonymous which is just false. Government could ask website/service for the token or account information then use timestamp or token then combining with "provider" logs, your identity will be exposed.

EUID has another problem which is letting all countries implement system, which is wasteful duplication effort so this probably will be outsourced and to same company to reduce duplication efforts. Then it'll be centralized and they happen be collecting telemetry data for "experience improvements" as everysite out there do.

I haven't even mentioned biggest problems like requiring attestation Apple/Google. While spec doesn't require it, but the likehood country's app requiring it will be very high.


The beauty of the EU is that you only need one county of upstanding people to get a permissible good implementation.

It will probably be a small country, one that is known to give no fucks about big tech.


> The only real issue is the wallet app and device binding. Because a compromised device could allow credentials to be transferred some form of attestation of device and wallet app is required. In practice this means no rooted/jailbroken phones.

Yeah, and no Linux PCs, no custom builds of web browsers (which would effectively become open source in theory only)—basically the end of any kind of open platform. I would much rather just scan my ID!


Oh you know it would be both not either.


The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID.

IMO, there are two other issues that need to be solved. The major one is that there should be some way to do attestation of devices that are not Google-certified Android or iOS. If this does not happen, the smartphone duopoly is permanently entrenched and not a fair/free market anymore. There is no way to use a smartphone without basically losing your privacy to Google/Apple and given the increasing importance of online services it's becoming increasingly impossible to live without a smartphone.

It was very disheartening that the EU reference implementation was rolled out with only Play Integrity and Apple's counterpart. IMO, this should have been solved before the reference implementation was rolled out to member countries, because many of them won't bother to go beyond that [1]. It is also completely counterproductive when it comes to EU tech sovereignty. There is a group of pioneers that are growing the sovereign ecosystems and then you cut them off.

The second, perhaps lesser, problem is that the security story is not super strong, because most Android phones do not even have a secure enclave (outside Pixel and Samsung flagships/A5x, there are very few). Instead they rely on TrustZone etc. which are regularly targeted by side-channel attacks, etc. Ironically, GrapheneOS is cut off from most of these systems (because Google Play Integrity), while it actually requires a secure enclave and is more secure than... well I guess every other smartphone.

[1] There is some hope, e.g. the developers of the Dutch identity wallet acknowledge the issue and are open to supporting alternative systems.


> The major one is that there should be some way to do attestation of devices that are not Google-certified Android or iOS.

IMO, just don't do the proof of possession. If I have the token that says I am an adult, I can use it to be considered an adult online. If someone requests millions of tokens and sells them, then punish that someone. It's not very hard to find them: they have to sell those tokens somewhere.

Also don't try to solve the VPN issue: I highly doubt most kids will use VPNs to access social media, and accessing porn isn't that hard if you are capable of running a VPN.

Again, I can consider age verification as some kind of "inconvenience for under age people". But the age verification that works 100% of the time is a problem, as you say it will lock people out with remote attestation and that is not acceptable.


> The government issues an eID to your wallet

I'll stop you right here. I don't want to be forced to use a government issued ID — one the administration can revoke at a whim, one that will certainly be backdoored by intelligence agencies including the ones they haven't told you yet — just so I can talk to my friends online.

It's insanity that we are asking the state to regulate personal identity — and trust them with it - in 2026 on hacker news.


Don't you have a SIM card?


Most non phone computers do not have a SIM. And some countries allow to buy a SIM without identification.


> A public/private key-pair is generated by the secure enclave in your phone

This is completely unacceptable. In practice, this solution means a locked down device, probably controlled by Google or Apple.

The Internet has existed without identity or age verification for more than 30 years, and there is no reason to change that.


Which part of that is avoiding the distopian control?

the very first line, government issued digital id - we have been avoiding that for a very long time

how does this work on an open source operating system?


> Which part of that is avoiding the distopian control?

Your ID is already controlled by your government, and we don't call that dystopian control. With privacy-preserving age verification online, the government doesn't learn what you do with the cryptographic token that proves that you are old enough, and the website doesn't learn who you are. So it's exactly the same situation as today, except that now there is age verification.

> how does this work on an open source operating system?

First, it can be open source and have DRM and attestation. Android is open source, for instance.

This said, I hate the idea of remote attestation. And for age verification, I strongly believe that it is not needed. We don't need to make it work everywhere all the time, it just needs to help. I can imagine a privacy-preserving age verification system that helps with some problems (e.g. make social media or porn less accessible to kids) without bringing dystopian control and without making it super hard for adults to access social media and porn.

But I absolutely hate the idea of remote attestation.


> Your ID is already controlled by your government, and we don't call that dystopian control.

The expression "papers, please", a classic exemplar of dystopian control, is referring to what?

> First, it can be open source and have DRM and attestation. Android is open source, for instance.

When people say "open source" in this context they mean that the user or third parties can make changes to the system, not that the source code is thrown over the wall from time to time. The situation with Android is exactly the thing that we don't want.


> When people say "open source" in this context

Do they? My experience is that often they don't know what "open source" means in the context of software or that they don't know that the system they were criticising is actually open source.


It's not hard to not realize that Android is open source because doing it that way compromises nearly all of the advantages of something open source.


Does it, though? There are many, many, many AOSP-based systems. DJI remote controllers run AOSP, and of course there is LineageOS and GrapheneOS.

I can read the sources of AOSP, I can modify it, build it and install it on my device.

I can read the sources of AOSP to find bugs or security issues.

I can read the sources of AOSP to understand how it works and get inspiration for my own projects.

What does it compromise to you?

Maybe you're unhappy about the fact that it is not open development, but that's a completely different question and many, many open source projects are like that. I have offered PRs to multiple projects that never bothered reviewing them because they did not care, and that is exactly how open source works.

There are so many reasons to complain about Google, the fact that Android is open source is not one of them.


The California age "attestation" system is a really good idea. It just delegates to the device owner, assuming anyone who can buy a device is the parent or is close enough to being an adult it doesn't matter. And then it makes using any other signal illegal unless you're a bank.


> Your ID is already controlled by your government

In the US, there are no national IDs, each state is responsible for their own. Transitioning to a national ID is not even legal currently, it would require a constitutional amendment... and I think most people do not want that for multiple reasons.


I am not sure how that is relevant, rather than nitpicking.

In the EU, there is no concept of EU ID, each country is responsible for their own.

Still, there is a governing entity that is responsible for your ID and controls it. Unless a US state is not a "governing entity"? Though the head of a US state is called a "governor", right?


I think the relevance is that there can be no requirement by the US federal government for states to support any particular technology, which makes age verification continue to be a state-specific unregulated free-for-all.

Even the REAL ID Act only mandated requirements for a license when used to enter government owned or regulated property, and states can still choose not to abide by it.


Yes but that is irrelevant to the discussion here. It doesn't matter if the federal government runs the age verification or if each government does it. The point remains: that "governing entity" already knows your identity, so by running an age verification service they do not learn your identity.


there is no single government id in the UK at the moment, they currently do not control my identity

you specifically talked about an OS without user changeable software, thats the definition of open source


> there is no single government id in the UK at the moment, they currently do not control my identity

Wait, so you live in a country where there is no government that can provide an ID? How does it work when you travel abroad? Do you have multiple legal identities, with different names and nationalities, that cannot be individually tracked back to one government?

> you specifically talked about an OS without user changeable software, thats the definition of open source

No? Open source is about your ability to reuse the code. You can modify and install Android (or let's say AOSP) on most Android devices (look at the list of devices supported by LineageOS for instance).

The one thing you cannot do is modify it and get your changes signed by Google.

Remote attestation is about preventing you from leveraging open source software, but the software is still open source.


they provide passports for travel, driving licences for driving, national insurance number for taxes, but its not a single id that everyone is required to have

there is no point in it being open source if i cannot modify and run it


> they provide passports for travel, driving licences for driving, national insurance number for taxes, but its not a single id that everyone is required to have

I am not sure what point you are trying to make. The government controls your passport, your driving licence, your national insurance number for taxes, but because those are 3 different IDs, it doesn't count as "your government controls your ID"?

Feels like you're just nitpicking for the sake of it.

> there is no point in it being open source if i cannot modify and run it

Well I for sure hate the idea of remote attestation, I agree with you on that. I was just pointing out that saying "it's not possible to have remote attestation on an open source system" is wrong: it's possible, that's a big part of why "they" like remote attestation: because they have control even if you can tamper with your system.


Couldn't the public key be used as an identifier for tracking?


I don't want an eID established on the net. It isn't sensible design. It would only work for the legal offerings and those just can send a header and devices need to block any communication if device is in kidmode. Easy, efficient, better engineering.

Illegal offerings won't do either of course. That can only be achieved by whitelisting a kid-net. Resource intensive, but only choice if you want unsupervised kid safety on the net. Because the net isn't kid safe and it cannot be by design. So you would need to create a subnet with actively moderated content.

Any other proposed mechanism has severe flaws. The only other choice is active parenting, which is unrealistic. An internet ID solves nothing, but creates more problems.


What do you mean by "active parenting", and why is it unrealistic?

(Do you mean something specific like HHS' Active Parenting™? https://preventionservices.acf.hhs.gov/programs/744/show )


With active parenting I meant parents thoroughly checking the sites their kids have access to. Nothing parents can shoulder these days in my opinion since it is a very technical and fast moving problem. Some parents could do it, but the vast majority probably wouldn't.

Most approachable is the device having some kid mode. In this mode online platforms need to send a respective header to authorise the content as kid friendly.

If that is missing, access isn't possible. In this case parents just need to check that the devices of their kids are configured properly.


Compared to current age verification laws, I agree that a self-declared header would be better both technically and socially. Parenting is daunting for the vast majority (including myself), and that solution would make it easier for parents to supervise their children, but I strongly disagree it's unrealistic to generally do so today.


Congratulations, you just outlawed open computing thus still getting us into the coming dystopia. This is not an acceptable solution especially to a problem that doesn't really need to be solved by age verification.


How does this work without a phone? I do 99% of my computer work, like now, not on a phone.

Do regular desktop and laptop computers have the same secure enclave feature?


No, none of the commodity pcs or laptops come close to what Apple iPhone or Google Pixel hardware offers. Some have some sort of the secure enclave but it's not as safe.


rats, so this isn't really a viable solution.


No you just can't do it there. Scan a QR code on your phone.


>The government issues an eID to your wallet

So people in dubious legal circumstances are locked out the internet?


There is no real practical difference between ‘attested devices’ and scanning ID…


What about at the device level?

“You must be this tall to ride this ride”

“ you must be 18 to own an iPhone 18+ “

I apologize for the drive-by question, and I appreciate your takes!


This would run into the same deal as VINs in the real world being tied to licenses, or serial numbers to guns. But the car equivalent of VMs/open hardware/custom firmware (imagine a $7 pi zero flashed with lineageOS “overage phone”) then becomes equivalent to a gun without a serial number, and suddenly open source/hardware people are felons and there is insane amount of control on hardware and software like it’s 1982.

This assumes that the government would be able to verify independently a phone serial number so that people’s IDs aren’t leaked. If not, then you’re back to the same thing as before since “drivers licenses” are stored by sites and shared around with advertisers


> which contains the device public key

And there it is.


The government still gets to know what you're doing online. How is that privacy?


Nope they don't. That's the whole point of privacy-preserving age verification.

Technically it is possible. The complaint that people have is that they don't trust that any government will get it right. But it is technically possible with known cryptography.


Ah ok. I understand now. The website isn't making an additional request to the government to verify that the credentials you gave are real. The authenticity is built into the signature.


Yes exactly. With the caveat that an untraceable token can be passed to someone else. So then there are the shady remote attestation schemes that try to make sure that only your smartphone can use that token that was generated for you, and this is very very bad in my opinion.

But if you accept the caveat (like we do for cigarettes, where an adult can buy cigarettes and then give them to a kid), you don't need to remote attestation part.


No, it isn't technically possible. With true anonymity you can also re-sell tokens making them meaningless. If you prevent token sharing then you cannot have real anonymity. You can't have your cake and eat it too.

And if you have to trust the government to get it right then you have already lost because they are definitely motivated to NOT get it right because they WANT to track you.


> No, it isn't technically possible

Of course it is. Read the sentence again:

> The government still gets to know what you're doing online. How is that privacy?

It is technically possible to achieve that without the government knowing what you are doing online.

> With true anonymity you can also re-sell tokens making them meaningless.

You can re-sell tokens, just like you can re-sell cigarettes. Does that make the system meaningless? Harder to prove.

> And if you have to trust the government to get it right

The whole point is that you don't have to trust; you can verify. The system has to be open source of course.

It doesn't mean that they will do it right, but it is technically possible.


> The website only sees the ‘over_18’ attribute

I don't believe this.


So now I have to have a mobile phone?


And one you don't fully own/control. Fully owned devices will be unsupported, obviously.


Sounds like what a government issued card should be used for, which seems fine


Could probably be implemented by a smartcard or yubikey-like device as well. Shoot, just build it into my state issued ID card.


Do you know how hard it was to get RealID rolled out?

And now you're going to tell every state to do it again, but this time it's got a chip in it so "just trust the government, man".

This will go well.


It will go fine, because everything you want to do will require it. Even if you don't strictly have to, you will be effectively ostracized. Transit, entertainment, productivity tools. Haven't you noticed that things that have previously been easy to do are much harder now, even before this has rolled out? Like providing a government ID to visit a museum, for example. Or getting an email address. Using claude.


They've had some practice now, so next time will go better.

RealID is completely optional anyways. Just like organ donation and using the internet.


I feel the idea of public key encryption could be done without a phone but the device locking makes it harder to transfer the token off device. Like the parent comment said, I think 90% is all we can aim for. Nothing is going to be perfect.


You can have an ID card. Just like for buying alcohol and cigarettes.


What do you think is the trade off?

You need mobile phone anyway.


Do I? And if so why?


Yes. Cover 90% of cases. Maybe browser and RFID reader for passport is also possible.


Identity wallets can be made to work anywhere.


Secure Enclave on a mobile phone, or an NFC smart card both work fine. It could be your passport, drivers license, national ID, whatever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: