←back to thread

94 points mikece | 1 comments | | HN request time: 0.208s | source
Show context
ineptech ◴[] No.44398335[source]
Would it not be reasonable and safe and private to implement age verification through login.gov? An Oauth implementation that knows your identity and age can produce a verifiable token that attests your age but not identity. The only way your identity would leak would be if both the porn site and the oauth retain the tokens (which they would both claim not to do else no one would use this), and the attacker gets access to both.

I know it's unlikely to happen because of America's (misguided IMO) extreme distaste for digital government ID, but it seems like the current solution (people uploading pictures of their driver's license to porn websites) is worse in every possible way.

replies(3): >>44398708 #>>44398763 #>>44399521 #
1. jonahbenton ◴[] No.44399521[source]
Yes, uploading IDs to commercial entities (porn or not) is terrible. Coinbase's recent KYC breach is going to lead to a metric ton of identity theft. While there used to be penalties for securities fraud- no more of that under Trump- there are no penalties for privacy violations and until there are, commercially pervasive KYC is an absolutely awful idea.

Wrt login.gov, as someone who has contracted with fedgov and knows some former 18f people, absolutely excellent humans and technologists- their work notwithstanding, Musk's criminal rampage through fedgov databases and US SC complacence with same has turned me into a rabid libertarian. Cities and states are set up to- and should be funded to- provide individual constituent service. Fedgov is just not.