Privacy and Technology Policies

EFF: Zero-Knowledge Proofs Are Not a Magic Solution for Age Verification

The Electronic Frontier Foundation argues that using zero-knowledge proofs to verify users’ ages does not address privacy and security risks and may add a centralized point of failure and misuse. The foundation cites vulnerabilities that emerged in a trial of the European digital identity wallet, including repeated acceptance of the same token without a new verification.

2026-08-18
5 min read
16 views
فريق تحرير certi.news
EFF: Zero-Knowledge Proofs Are Not a Magic Solution for Age Verification

The Electronic Frontier Foundation (EFF) says that zero-knowledge proofs (ZKPs) do not provide a comprehensive solution to the problem of verifying the age of internet users, despite sometimes being presented as a way to prove that a user is an adult without exposing personal data. The foundation believes that these systems may fail to achieve their primary objective while simultaneously creating new risks to privacy, security, and freedom of access to services.

These positions come at a time when age-verification laws are expanding. According to the article, about half of the U.S. states have a law related to verifying the ages of internet users, while federal proposals such as the KIDS Act and the Kids Online Safety Act (KOSA) are advancing. In the European Union, member states are moving toward providing age-verification infrastructure through a centralized application by the end of 2026, while Australia is already implementing a broad restriction.

From Individual Privacy to a Centralized Control Point

EFF acknowledges that age verification through ZKPs appears, in its ideal form, to reveal less data than methods that require every website or application to view user information. Instead of sharing a date of birth or identity document with every service, a token could theoretically be issued to prove that a person is above a certain age without revealing other details.

However, the foundation believes that this design does not eliminate the need for an entity to issue the token or verify its holder’s age. With every use, a persistent link may arise between the token and the entity that issued it. If the issuing entity can record credential use, a metadata record may be created showing which services the user accesses. The entity may also face government pressure to block a person’s access to a particular service, or become a centralized gateway that effectively controls an important part of access to the internet.

How Does the Technology Work?

Zero-knowledge proofs allow one device to prove the validity of information to another device without revealing the information itself. The first device proves a mathematical commitment to the information, and the second device then poses challenges that can be answered correctly only if the original information is valid. To avoid the slowness of repeated interaction between the two devices, applications use a non-interactive version of this process.

The version most closely associated with age-verification cases is zk-SNARK. In it, the answer is converted into a compact value using hashing, so that the result is theoretically difficult to predict or manipulate. At best, this mechanism can prove that a user is an adult or a child without revealing additional personal information. However, EFF says that real-world testing has shown that the technology’s mathematical properties alone are not sufficient to solve implementation and operational problems.

What Did the European Union Trial Reveal?

By the end of 2026, the European Union’s 27 countries are expected to have age-verification infrastructure through a “mini-wallet” application within the EUDI Wallet, the European digital identity wallet. EFF says that the version of the wallet being rolled out to users does not actually activate ZKP features, except for a closed trial version or prototype that most users cannot access.

According to the article, a security researcher also found a way to bypass the system using a simple Chrome browser extension. The extension was able to trick the application into accepting the same “over 18” token repeatedly, without requesting a new verification each time. EFF also cites an open letter signed by more than 400 security researchers, which warned that age-verification checkpoints could cause more harm than benefit even when designed with privacy in mind.

The risks become more sensitive if the mini-wallet is fully integrated with the EUDI Wallet, because any potential failure would not be limited to age data. The wallet could also contain passports, driver’s licenses, travel information, and financial data, expanding the impact of an attack or misuse.

Why Does This Debate Matter?

The practical point is that data protection does not depend on the ZKP algorithm alone, but on the entity that issues the credential, how it is stored, the possibility of tracking its use, and the safeguards that prevent its reuse or the bypassing of the verification mechanism. EFF therefore concludes that any mandatory age-verification system cannot simultaneously guarantee privacy, accuracy, and comprehensive coverage without introducing significant security risks.

Because the article expresses EFF’s position, its rejection of mandatory age verification represents a political and technical opinion attributed to the foundation, not the result of a general consensus. However, the examples concerning the activation of ZKPs and the repeated acceptance of the token provide a practical basis for reviewing the promises of these systems before expanding their use.

News source
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news