frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Free and Anonymous Age Verification Demo

https://www.youtube.com/watch?v=MmcUJ5u65Q0
1•jwally•4mo ago
========================

What is this?

========================

A short demo showing how a merchant can outsource age verification to a trusted institution (bank/KYC provider) with minimal cost and minimal data leakage. The user never hands the merchant their identity — only signed attestations like over_18: true. It’s a pragmatic build: WebAuthn proves token ownership; ECDSA signatures from the bank prove attestation integrity.

========================

Why Does It Matter?

========================

Age verification is usually either privacy-destroying (share DOB/SSN) or expensive. Banks already do KYC for many customers. If they can safely issue attestations that protect privacy and are cryptographically verifiable, merchants get compliance without storing PII and users keep their data. Age Verification becomes less useful in de facto outlawing free speech.

========================

How does it work (user-flow)?

========================

1) Go to https://app.hornpub.click

2) Click Generate PassKey

3) Copy the PassKey (there's a button for you)

4) Click on The Iron Bank link

5) Click on "Age Verification"

6) Make up some credentials to log in with - (un: xxx, pw: xxx, 2fa: 111111)

7) Paste your token into the TextArea

8) Copy the bank's token

9) Go back to HornPub (click button or whatever)

10) Paste the token into the "Complete Verification" text-area

11) Click the "Complete Verification" button

12) Complete the PassKey flow, and access the site

========================

How does it work (merchant-flow)?

========================

1) The user creates a PassKey, and you extract the key's ID and PublicKey

2) Base64 encode the {id, PublicKey} and let the user copy it

3) The user goes to their Bank or KYC provider.

4) The user provides the Bank's token

5) Have the user perform a WebAuthn Authentication by extracting the credential's Id and Public key from the bank's data. Use the entire bank's payload as your WebAuthn Challenge

6) Send the Authentication payload to the server

7) Verify the WebAuthn Authentication - this proves the user didn't create a token and sell it

8) Verify the bank's signature. You control what banks you accept. This proves it wasn't tampered with

9) Verify a salted-hash of the user's IP address.

========================

How does it work (bank-flow)?

========================

1) Publish your ECDSA signing key at /.well-known/keys

2) Accept a string payload from your user that you will sign. You do not have to verify or look at it.

3) Look the user up and add age attestations of `over_18:boolean` and `over_21:boolean`

4) Create a nonce, and provide it and sha256(nonce:ip) in your signature target

5) Sign base64Encode({over_18, over_21, nonce, ipHash, userPayload })

6) Provide the signature and signature-target to the user for them to copy back to the merchant site:

========================

Security Notes & Trade Offs

========================

WebAuthn proves the holder of the PassKey created the credential — prevents a user from inventing a credential and selling it.

ECDSA signatures from the bank prove the attestation came from an accepted bank and wasn’t tampered with. Merchant picks which banks to trust.

Nonce + IP hash minimize replay/copy-paste attacks. They do not make the system 100% subpoena-proof — logs and warrants can still correlate events.

Privacy: merchant receives boolean attestations only, not DOB or identity. Banks don't know where the user will use the token.

Statin drugs safer than previously thought

https://www.semafor.com/article/02/06/2026/statin-drugs-safer-than-previously-thought
1•stareatgoats•1m ago•0 comments

Handy when you just want to distract yourself for a moment

https://d6.h5go.life/
1•TrendSpotterPro•2m ago•0 comments

More States Are Taking Aim at a Controversial Early Reading Method

https://www.edweek.org/teaching-learning/more-states-are-taking-aim-at-a-controversial-early-read...
1•lelanthran•4m ago•0 comments

AI will not save developer productivity

https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html
1•indentit•9m ago•0 comments

How I do and don't use agents

https://twitter.com/jessfraz/status/2019975917863661760
1•tosh•15m ago•0 comments

BTDUex Safe? The Back End Withdrawal Anomalies

1•aoijfoqfw•17m ago•0 comments

Show HN: Compile-Time Vibe Coding

https://github.com/Michael-JB/vibecode
3•michaelchicory•20m ago•1 comments

Show HN: Ensemble – macOS App to Manage Claude Code Skills, MCPs, and Claude.md

https://github.com/O0000-code/Ensemble
1•IO0oI•23m ago•1 comments

PR to support XMPP channels in OpenClaw

https://github.com/openclaw/openclaw/pull/9741
1•mickael•24m ago•0 comments

Twenty: A Modern Alternative to Salesforce

https://github.com/twentyhq/twenty
1•tosh•25m ago•0 comments

Raspberry Pi: More memory-driven price rises

https://www.raspberrypi.com/news/more-memory-driven-price-rises/
1•calcifer•31m ago•0 comments

Level Up Your Gaming

https://d4.h5go.life/
1•LinkLens•35m ago•1 comments

Di.day is a movement to encourage people to ditch Big Tech

https://itsfoss.com/news/di-day-celebration/
3•MilnerRoute•36m ago•0 comments

Show HN: AI generated personal affirmations playing when your phone is locked

https://MyAffirmations.Guru
4•alaserm•37m ago•3 comments

Show HN: GTM MCP Server- Let AI Manage Your Google Tag Manager Containers

https://github.com/paolobietolini/gtm-mcp-server
1•paolobietolini•38m ago•0 comments

Launch of X (Twitter) API Pay-per-Use Pricing

https://devcommunity.x.com/t/announcing-the-launch-of-x-api-pay-per-use-pricing/256476
1•thinkingemote•38m ago•0 comments

Facebook seemingly randomly bans tons of users

https://old.reddit.com/r/facebookdisabledme/
1•dirteater_•40m ago•1 comments

Global Bird Count Event

https://www.birdcount.org/
1•downboots•40m ago•0 comments

What Is Ruliology?

https://writings.stephenwolfram.com/2026/01/what-is-ruliology/
2•soheilpro•42m ago•0 comments

Jon Stewart – One of My Favorite People – What Now? with Trevor Noah Podcast [video]

https://www.youtube.com/watch?v=44uC12g9ZVk
2•consumer451•45m ago•0 comments

P2P crypto exchange development company

1•sonniya•58m ago•0 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
2•jesperordrup•1h ago•0 comments

Write for Your Readers Even If They Are Agents

https://commonsware.com/blog/2026/02/06/write-for-your-readers-even-if-they-are-agents.html
1•ingve•1h ago•0 comments

Knowledge-Creating LLMs

https://tecunningham.github.io/posts/2026-01-29-knowledge-creating-llms.html
1•salkahfi•1h ago•0 comments

Maple Mono: Smooth your coding flow

https://font.subf.dev/en/
1•signa11•1h ago•0 comments

Sid Meier's System for Real-Time Music Composition and Synthesis

https://patents.google.com/patent/US5496962A/en
1•GaryBluto•1h ago•1 comments

Show HN: Slop News – HN front page now, but it's all slop

https://dosaygo-studio.github.io/hn-front-page-2035/slop-news
7•keepamovin•1h ago•1 comments

Show HN: Empusa – Visual debugger to catch and resume AI agent retry loops

https://github.com/justin55afdfdsf5ds45f4ds5f45ds4/EmpusaAI
1•justinlord•1h ago•0 comments

Show HN: Bitcoin wallet on NXP SE050 secure element, Tor-only open source

https://github.com/0xdeadbeefnetwork/sigil-web
2•sickthecat•1h ago•1 comments

White House Explores Opening Antitrust Probe on Homebuilders

https://www.bloomberg.com/news/articles/2026-02-06/white-house-explores-opening-antitrust-probe-i...
1•petethomas•1h ago•0 comments