this post was submitted on 15 Apr 2026
771 points (98.9% liked)
Technology
83831 readers
3661 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Well they could do it the right way where, for example, you go to your city hall to get a certificate of age where they check your ID. Then some cryptography happens so you only enter a public key from that certificate on a website or OS to verify your age.
The website or OS doesn’t check your ID. City hall doesn’t know your browsing history.
But I’m not fooling myself, that’s not the point of such a law.
no implementation of personal ID for internet access will ever be "correct."
That's not true. It's simple if all you actually want is age verification.
You go in to the government building and show your ID. Seeing you are 18 or older you get to go to another room where they don't check your ID, just give you a token saying the one holding it is over 18. Make the token like a FIDO key where you have a pin you set yourself.
There is an air gap between the validation and the token creation so there is no way to go from token to ID. You make the key use a pin so we consider it to be once usable by one person.
The issue is not about the technology. The issue is that we all know this has nothing to do with kids getting on porn sites.
Now you have trusted the user not to provide the PIN to another, and the implementation is no longer correct. You'd at least need to use biometrics to tie the key to the person.
Would these tokens be unique per website visit? Are they generated by the user or the government?
Exactly. Digital ID verification is in no way comparable to physical ID verification.
Never say never there is ALWAYS a way to do things right. But our government is too stupid to do it. So it might as well be impossible. Kek