Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is trusting both Apple and the client, and also only works for iPhone.

We can do better with zero-knowledge-proof-based schemes, which also allow securely decoupling issuance/certification from online verification.

E.g. https://linc.cnil.fr/en/demonstration-privacy-preserving-age...



It's a privacy issue as long as Jim's Blackmail and Certificates, Inc. knows who they've certified.


I don't see why Google/Android can't implement the same solution.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: