Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://datatracker.ietf.org/wg/privacypass/about/

Perhaps a system like Privacy Pass would be ideal. Where a verifier generates a verified client a number of redeemable signed tokens for a session, but when presented by a client, the site doesn't know who that token was issued to, but they know they authenticated this person and can verify they made the token. Therefore they get access.



You're looking for a technical solution to a political problem. This tech is useless the second a law is passed that identities have to be logged. It's also useless if implementers decide to collect identifying information without telling you.


That also weakens circumventability. What's stopping me to sell my signed tokens to the highest bidder on ebay?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: