The service provider could even generate a certificate request that the age verification entity signs (again, with no identifying information, other than "I need an age verification signature, please"). That certificate would only be valid for that specific service provider and can't be re-used.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: