Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The door guard needs to validate your face matches your ID. In you example you provide the door guard with proof that you are in real-time communication with a real ID, not that it's yours.

A challenge response would be the door guard provides you with a picture of yourself, and then you run their verification code with the picture and your ID.

However, you would also want to take into account multi-venue barring lists, which would require you to provide that you're not on a list of people (that you don't have access to).

In reality, this gets complicated very fast, and I would much prefer to just show the door guard my ID rather than involve computers in any way shape or form, let alone ZK systems.



The app shows your face on it and says it is 21+.


That isn't a challenge/response flow, that's the app on your device asserting something in isolation.


The challenge is from the security guard who won't let you into the club without proof that you're 21+.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: