• kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    1 天前

    They wouldn’t see what sites you give the tokens to — unless those sites choose to phone home, for some reason.

    • You log in to the government site
    • You ask for a token to prove your age/gender/whatever
    • You copy the token
    • You go to the age/gender-restricted site
    • You provide the token
    • The restricted site asks the government site how to verify any arbitrary token (but doesn’t mention your specific token)
    • The restricted site verifies the token