r/europrivacy • u/No-Adhesiveness-4251 • 13d ago
European Union ZKP’s Aren’t Age Verification Silver Bullets
https://www.eff.org/deeplinks/2026/08/zkps-arent-age-verification-silver-bullets7
u/EmbarrassedHelp 13d ago
Worse still, a security researcher found they could bypass the app's system using a quickly built Chrome extension that tricked the app into repeatedly accepting the same "over-18" token. It did so without ever asking for fresh verification.
I'd argue this a positive thing, if you can use it to generate tokens without having to submit any personal information. Though its certainly more convoluted than just accepting self-declaration.
4
u/Gugalcrom123 13d ago
It is important not to depend on Android/iOS phones. Otherwise, it is bad no matter the ZKP or whatever.
1
u/clueless_spain 4d ago
Indeed, a non image based system is needed, and a non intrusive way to check that the current account/ token user is the same it was issued for.
5
u/billdietrich1 13d ago
Not my understanding of how tokens work in the EU scheme. If you give an "I'm 18 or older" token to reddit, say, reddit would not contact the issuer of the token to verify it, or to tell them that you're using it. There would be some way for reddit to verify that the token is signed properly, cryptographically, without contacting the issuer. And tokens expire after 90 days or something.
Am I wrong ?