Current Region:
Global

In their latest publication in a series tackling age assurance, "Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets" the Electronic Frontier Foundation (EFF) base their critique of a proven cryptographic technology entirely on the potential for it being deployed badly or maliciously.

Zero-Knowledge Proofs have worked effectively for decades. ZKPs do not inherently require a single issuer or centralised infrastructure. A properly designed system can prevent the issuer from learning where a proof is presented and prevent relying services from linking separate presentations. Those are architectural and governance choices. The issue isn't the underlying technology; it's that it is possible to implement it in a way that undermines the valuable property it is designed to create - anonymity.

This is why we support certification and audit against international standards, so systems are subject to regular third-party scrutiny, offering assurance that the claims made about their privacy, security and accuracy are valid. ISO has now published both its framework for age assurance systems, ISO/IEC 27566-1, and guidance on privacy preservation using zero-knowledge proofs, ISO/IEC 27565.

Even, for example, Signal, while designed to guarantee secrecy, could theoretically be altered to breach their privacy promise. Double-blind age assurance, under which the age provider does not know which service is being accessed and the service does not learn the user’s identity, is no different. If designed well and implemented properly, ZKP or an equivalent privacy-enhancing technology (PET) delivers the privacy regulators, such as the French CNIL - Commission Nationale de l'Informatique et des Libertés which pioneered applying this concept to age assurance, demand.

A badly baked cake does not mean its ingredients are defective.

Iain Corby, Executive Director