Laeserin
· 1w
I find it qurious that you first said it was a shitty concept because it is possible to trace back to the original person. Then I say it isn't possible to trace back, and now you say, Wow, that's a sh...
Well, the original post wasn't meant to be quite as conclusive as you make it out to be. I was just trying to figure out what's going on.
It seemed useless if it's traceable. Then you told me that it's not traceable. So that then made me wonder what use cases there are for an ID that you can present in such a way that it's not possible for anyone to determine the identity of the owner.
You can't cryptographically confirm that you are providing the service to the actual owner of the ID, but maybe you can confirm that you are providing the service to a device where the ID is installed? I.e. maybe you can confirm something like
"I'm providing this service to a device that has an ID installed for someone for which the EU attests that they are over 18."
And it's assumed that the owner of the ID is in possession of that device, and that assumption then justifies the idea that you are providing the service to the owner.
If that's the picture, the EU will have to ensure that the ID for a person can only be installed on devices that the EU has confirmed are controlled by that person. It's a device-bound ID, and it can piggy-back on the mechanisms we currently have for binding devices to their owners.
♥️1