Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

How To Prove Something About Yourself Without Showing It

Verification systems increasingly answer a single question rather than handing over a document, and the mechanism relies on a signed claim the checker cannot read fully.

Individual using a VPN application on a laptop at a desk in a modern office setting.
Photograph by Dan Nelson via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Proving eligibility usually means showing a document containing far more than the fact required. Cryptographic approaches allow the answer without the document, and they are being deployed gradually.

Documents disclose everything at once

An identity document proves a date of birth by also revealing a name, an address, a document number and a photograph.

The verifier needs one fact and receives a complete profile, which then exists in whatever system recorded the check.

Copies accumulate across many unrelated checks, and each copy is a potential breach containing more information than the transaction ever required.

A signed credential separates issuer from verifier

The alternative issues a credential signed by an authority and held by the individual. The signature proves the contents were not altered.

Presenting it to a verifier requires no contact with the issuer, so the issuer does not learn where or when the credential was used.

That separation is the significant design property. A system where the issuer is consulted on every check produces a complete log of the holder's activity.

Selective disclosure reveals one field

Credentials can be structured so each attribute is signed separately, allowing the holder to present some fields and withhold others while the signature remains verifiable.

More advanced constructions go further, proving a statement about an attribute without revealing the attribute itself.

Under such a scheme a verifier learns that a threshold is met and nothing else. There is no date to store and nothing to leak later.

Linkability is the remaining weakness

If the same credential is presented repeatedly, verifiers can recognise it as the same one, and comparing notes reconstructs a history of use.

Designs address this by issuing many single-use presentations, or by generating a fresh proof each time that cannot be correlated with previous ones.

Whether an implementation does this is not visible to the user, and it is the difference between genuine unlinkability and a durable identifier under another name.

Adoption depends on the boring parts

The cryptography has been understood for years. The difficulty is agreeing formats, issuing credentials at scale and giving verifiers a reason to accept them.

Recovery is the hardest piece, since a credential held only on a device is lost with the device, and a recoverable copy held centrally reintroduces the issuer.

Progress is therefore slow and unevenly distributed, and requirements differ substantially between jurisdictions and change as rules are revised.

Questions readers ask

What happens if I lose my phone?

If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.

Is a passkey the same as biometric login?

No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.

Data & Privacysecurityauthenticationcryptographyaccounts
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas