Post #3276908
2026-06-01 23:31 UTC
Replies (2)
-
@crazyeddie@mastodon.social 2026-06-01 23:38
@ansuz@gts.cryptography.dog @kbal@fedia.io @mullvadnet@mastodon.online The credential cannot be transferred because it's attached to a guaranteed unique ID that is the entity the credential is for and this with the values in the credential are cryptographically signed by the entity that validated the actual content or whatever. Any attempt to "transfer" is going to invalidate the signature. It can be copied around quite freely though. Hence the ZKP part meant to hide the actual birthday. Right now I'm not really convinced it does so.
-
@kbal@fedia.io 2026-06-02 00:14
Nobody has to talk to anyone else, but the problem with the situation you've described is that they can choose to do so. Whatever semblance of anonymity is provided that way is not strong enough to deserve the appellation of "zero knowledge". That would imply mathematical certainty of it, not just a system where you're assigned a unique ID and a record is kept of it but the central authority solemnly promises not to tell anyone who it belongs to.