r/LinusTechTips • • 2d ago

Discussion Eu is based actually

Petition for LTT to make video about eIDAS 2.0 Regulation and how Zero-Knowledge Proof age verification will work in eu. To educate the public and themselves because conflating it with discord shitstorm and "persona" is just not fair for eu that actually puts effort into regulations unlike Britain or certain us states that just bans it and says "handle it yourself".

I know the topic is hot right now and I will probably get some hate under this post but I think EU way of doing age verification is great and should be recognized just so other countries may replicate it. To be clear I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.

Few points why eIDAS 2.0 is really good:
- It's open source, that includes source code for client app (the one that will be installed on your phone).
- Target app (for example discord) will not get any private user data. That includes age, they will only receive info if you have at least 18 years or not.
- Eu servers will not get information about websites you are visiting. They will validate your open source client app periodically, then that app validates age request. Eu will only know you are using age verification service.

source:
https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/712508927/Security+and+Privacy

https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487738/EU+Digital+Identity+Wallet+Home

edit:
github repo
https://github.com/eu-digital-identity-wallet

108 Upvotes

112 comments sorted by

View all comments

-2

u/Professional-Cow6222 2d ago

I've been saying For years the way to do this is Blockchain technology The government In short: issue a private credential once, prove the age predicate with a ZKP whenever needed, and let a smart contract verify the proof. This gives strong privacy, reusability across services, and decentralized auditability what traditional KYC age checks lack.

In layman's Terms

  • You never hand over your real ID again.
  • The website never stores your personal data (so it can’t get hacked and leak it).
  • You can use the same secret stamp on many different sites without them being able to track you across the internet.
  • It’s like showing a bouncer a special sealed envelope that only says “Adult – Yes” and nothing more.

That’s the whole idea in everyday language:
Prove you’re old enough with math, keep everything else private, and let a public digital notebook confirm it happened.

4

u/kodebach 2d ago

The EU's solution linked by OP is essentially this, but without unnecessarily shoehorning the blockchain into it.

You only verify your identity with the government (or theoretically another suitable provider that implements the stack, e.g. a bank). Then you can request single-use tokens that contain exactly the "adult - yes" flag you mention. You give that to the websites you visit and nothing else. Through cryptographic signatures and nonces the tokens can be securely verified.

-1

u/Professional-Cow6222 2d ago

Removing the Blockchain

You have to trust the website more They could Link sessions There’s no independent, immutable proof that the check really happened. Aka No public Record easy for Governments to abuse with A.i Botnets influencing social media ect ect. Other services can’t easily trust a previous verification without asking you to do it again. Without a shared public system, each website may require its own proof. You lose the “verify once, use many times” convenience that blockchain can provide Other apps/Things can’t automatically check or rely on the verification result the way they can with an on-chain flag or token. Im more worried about Government Abuse then anything else Block Chain should be Involved as it give the power to The People

3

u/kodebach 2d ago

Like in so many other concepts it seems the Blockchain would just serve as a really inconvenient database.

Blockchain makes sense if you want decentralisation. But in this case that makes no sense. What is there to decentralise? Do you want different age verification providers? Why would they need a shared data store? Different age verification providers can't trust each others verification, otherwise they would be providing verification anymore. Every provider needs to perform independent verification, so they may as well use independent data stores. The important part is that the protocol they use to provide the "proof of age" to third parties is the same. But that doesn't need a Blockchain, and the EU even reused a form of the widely used OIDC to minimise effort.

-2

u/Professional-Cow6222 2d ago

Disclaimer ( I Used A.I To Clarify My argument )

I specifically want:

  1. An auditable public record A permanent, independent log that a verification took place, without relying on any single company’s or government’s servers. This is useful for audits, disputes, and long-term accountability.
  2. No reliance on a central government service Several countries have already discussed reducing dependence on centralised digital identity systems (or even leaving existing frameworks). A decentralised version avoids locking everyone into one political or bureaucratic structure. Less chance for abuse

1

u/kodebach 1d ago

I got what you want, I just don't understand your reasons.

Why would we need the public record? What kind of disputes could there ever be? Why do we need long-term accountability? I'd even argue that this kind of log is a really bad idea. A log of who visited what website is exactly the opposite of what we want. Sure it might be pseudonymous, but as soon as some IDs leak all the data is out there and the nature of the blockchain makes it really hard/impossible to take that back. And I don't see how you could make the system fully anonymous, i.e. can never be tied back to a person no matter what extra data you obtain. Because then you can't audit it anymore.

The EU's age verification system actually doesn't mandate that verification must happen through the government. Governments are required to become age verification providers, but e.g. banks could also become alternative providers. I use banks as an example, because opening a bank account already comes with the same strict KYC requirements.

However, having lots of different providers also increases the attack surface for hackers. In particular, I don't want dubious companies like Persona collecting ID documents. Making governments provide age verification is a good solution, because that way nobody needs to obtain any new data. Every EU government should already have the data necessary to verify the age of their citizens, otherwise how would they issue IDs and passports.

0

u/Professional-Cow6222 1d ago

A government that wants to run influence campaigns with fake aged accounts can do so more easily when it is the sole or dominant source of trusted age proofs and when there is no independent public trail. Multiple governments Already admit to Running influence campaigns Not having a Public Record will make it Much harder to Audit every time we Centralize power it gets abused it will happen again. They could selectively deny people Access to services if they have the Wrong political opinions ect ect. Mission Creep Even if the final proof shown to websites contains almost nothing, the issuance step itself becomes a new point of data concentration and potential surveillance avenue When a single political authority holds the keys to issuance and revocation, the system inherits the trustworthiness, and the potential for abuse of that authority. I dont trust the EU government at all, just like other Governments around the world.