Damus
Laeserin · 4w
No. The tokens can't be tracked back to a particular person. They use blinded signatures and unique nonces.
inkan profile picture
If the tokens can't be tracked back to a particular person by anyone (including the EU itself), what prevents someone from using someone else's token?

Suppose your relay has an 18-and-over policy and I want to request access to it for my pubkey. I'm 17 and my friend is 19, so I ask my friend to send to you

(i) the pubkey for which I'm requesting access and
(ii) a token proving that the EU attests to the fact that the person who produced the token is over 18 (which my friend can produce)

It seems like you'd be giving the pubkey access to the relay based on this info, since the person who sent you the pubkey could prove that they were over 18. And I can then start posting notes to your relay with my pubkey, even though I'm only 17.

And nobody could ever prove that my friend participated in this deceptive arrangement, given that the token that was provided cannot be tracked back to my friend. The token could have come from anyone over 18.

You can see I'm still struggling with this conceptually ...
Laeserin · 4w
Someone could also just use your phone. Same as having someone else buy beer for you. This isn't a panacea.