Since July 2025 in Britain, if you want to look at ‘adult content’ online – or, increasingly, just use Reddit like a normal human being – you’re expected to upload your passport to some verification outfit you’ve never heard of or let an algorithm stare at your face and guess how old you are.
When this happened the Great British Public responded to it in a time-honoured fashion by downloading VPNs in such numbers that Proton’s sign-ups went up over 1,400% in a weekend and VPN apps filled half the App Store top 10. Half! The other half presumably being apps to tell you which VPN to download.
Meanwhile, over in Whitehall, the Government decided that what the nation is really crying out for is a shiny digital ID in a GOV.UK wallet. You may remember this idea from such previous hits as the National Identity Register, which got scrapped in 2010 after burning through hundreds of millions of pounds. Nearly three million people signed a petition against the new one. The Government’s response was to make it ‘optional’ and carry on regardless, because of course it was.
Now, here’s the bit that really does my head in.
These are presented as two separate problems – kids accessing porn, and proving who you are online – requiring two separate expensive solutions, at least one of which will inevitably be delivered late by a consultancy charging £2,000 a day for a graduate who’s just discovered what an API is.
They are not two problems. They are one problem. And – brace yourselves – it’s already been solved. The solution is sitting in your pocket right now, between Candy Crush and those three parking apps you’ve got that never work.
It’s called your banking app.
A radical proposal: use the thing that exists
Think about what a bank actually is for a moment. It’s an institution that is legally required to know exactly who you are. KYC – Know Your Customer – means every single account holder in this country has already trooped down to a branch or jabbed at an app with his or her passport and proof of address, and a regulated institution facing eye-watering fines if it gets this wrong has verified them. About 98% of UK adults have a current account. Your bank knows your date of birth with more certainty than your own mother, who frankly has been a bit vague about it since the third child arrived anyway.
Better still, banks already have the plumbing to share verified facts about you, with your consent, through an API. It’s called Open Banking. It exists. It works. It handles billions of calls a month. The regulator that supervises it exists. The security standards exist. The consent screens exist. Somebody has already done the hard bit, which in government IT terms is roughly equivalent to discovering the project finished early and under budget.
So here’s the proposal, and I want you to notice how it does not involve a single new quango, database, or ‘transformation programme’. You open your banking app. You tap ‘prove I’m over 18’. The app spits out a single-use cryptographic token – a code, a QR, whatever – that says precisely one thing: the holder of this is an adult. Not your name. Not your birthday. Not your account number. You show it to the website or other app. The website or other app checks the signature. In you go. Ten seconds, job done, and at no point did it have any idea who you are, or your bank learned what you’re into.
‘But the bank would know!’ No. It wouldn’t. That’s the point.
This is where it gets properly clever, and where every politician’s eyes will glaze over, so do try to keep up if you’re reading this in the Department for Science, Innovation and Acronyms.
There’s a class of cryptography called blind group signatures – invented by David Chaum in the 1980s, so it predates politician’s understanding of email by roughly 40 years and counting. The bank signs the token without seeing where it’ll be used. There is no log entry at NatWest saying what you did at 11:47 on a Tuesday, because the information was never there to log. The website or app, for its part, checks the token against the banking sector’s published keys and learns only that some regulated UK bank vouches for you. Not which one. Not who you are.
Tokens are single-use, so nobody can track you across sites. And because the bank knows half of nothing and the app or website knows the other half of nothing, there is no database to breach, no logs to leak onto a USB stick left on a train (HMRC, 2007, 25 million records, never forget), and nothing for a future government with authoritarian itchy fingers to requisition. The privacy isn’t a promise in a white paper. It’s maths. Promises get amended in committee. Maths doesn’t.
This isn’t even untested. Sweden and Norway have run national identity off bank infrastructure for two decades. Belgium too. Australia’s at it. The only flaw in their versions is that the bank can see where you log in – which is exactly the flaw the blind group signature stuff removes. We’d be taking a proven model and bolting on better privacy. I know, I know – Britain, learning from somewhere that’s done it successfully. Steady on.
The objections, dealt with before some think tank charges £40k to raise them
‘What about people without bank accounts?’ It’s about 1% of adults. And the Post Office, which already does in-person ID checks in every town in the land, issues them tokens over the counter. Next.
‘Teenagers will just nick their dad’s phone!’ Yes, and they can also nick their dad’s passport, credit card and car keys. No system in history has stopped a determined teenager with a compliant older sibling. The question is friction, and a biometric-locked banking app generating tokens that expire in minutes offers rather more of it than the current system, which a 14 year-old defeats with a free VPN in the time it takes to say ‘highly effective age assurance’.
‘Why would banks bother?’ A fraction of a penny per verification, paid by the website or app, multiplied by millions of checks a day. Banks have done more for less. And if they drag their feet, the FCA already has the precedent: it frogmarched the big nine into Open Banking once, it can do it again.
So naturally, we’ll do the other thing
The consultation on digital ID closed in May. Ministers are now deciding, and every instinct of Whitehall will be screaming at them to bolt age checks onto the GOV.UK wallet, centralise the lot, and announce it at conference to a standing ovation from people who’ve never read a privacy impact assessment in their lives.
It would mean asking the public to trust the state with precisely the thing three million of them just signed a petition saying they don’t trust the state with. Whereas the alternative – distributed across dozens of competing regulated banks, no new database, no new enrolment, privacy guaranteed by mathematics rather than by Darren Jones’s solemn word – is sitting there, fully formed, waiting for someone in Government to notice.
The technology is 40 years old. The banking rails are nine years old. The regulatory hammer already exists. Every single piece is on the board.
Which is precisely why I confidently predict we’ll spend at least £400 million building something worse. It’s what we do.
Phil Hendren writes the Dizzy Thinks Substack, where this article first appeared.


Discussion
Comments
This week across the site:
To join in with the discussion please make a donation to the Daily Sceptic.
Profanity and abuse will be removed and may lead to a permanent ban.
Good article. Deserves to be shared more widely.
Its too late – pornography is out of the pandora’s box.
However, and I know I am not alone with this, many of us don’t have banking apps on phones. Yes to online banking, no to on my phone – far too easy for a phone to go missing and you not realise it quickly enough! All of these were non-problems until someone decided that for our ‘ease and benefit’ (ie theirs) we should use these things.
As for social media – is it really that different to having your kids leave the house to ‘play’ and ‘hang our’ with friends but you really have no idea as to who with or where they are going? Same problem, different context. Grow up and parent!
Or they could just leave well alone and let parents, well parent, odd how rapists, grooming gangs, murderers on the street dont warrant the same attention
No. I don’t want to exchange any ID to look at content online.
If it’s required for pr0n it’ll eventually be required to do everything including commenting here.
I guess there are others here who still use cheques, do not do internet banking or have a banking app if only so my acs do not get hacked
If you can manage that then I applaud you sir, I’m genuinely amazed that it works for you.
I will admit that when I joined Substack, I let them have the unfortunate experience of looking at my face to confirm I am obviously a miserable old git, but at heart I am deeply opposed to verifying my age with any online site just to make Starmer get a warm fuzzy feeling in his trousers. I actually do very little social media, just Facebook for a few hobby pages (don’t laugh for model railways) and other than x click outs from here and Guido, I don’t do anything else. My Facebook account is more than sixteen years old, so presumably will not need verification. My preference is non-compliance, for millions of people to lose access to all these sites, with the loss of income for them. This will lead to a massive trade war between us and Trump and ultimately the master u-turner Starmer will back down in the face of such a huge cost to the UK.
Love it, seems sensoble practical effective and cheap, obviously they’ll never go for it.
I do not believe that whoever issues the online permit will not find out what we look at. And when they do they will restrict access or close out accounts – well, because they can and they are all hooked up to the political class globalists.
just going to this site, Daily Sceptic, will be enough reason to debank us. Think if they can collate all our online access. Credit limits lowered, bank accounts closed, we become no e persons.
But dont accept the banks as paragons. I am one of five UK resident tax payers, all Brits and all regulated at some time or other who formed a small UK holding company. Three of us are directors. HSBC demands evidence we are who we said we are every other year. They threaten account closure. We only need it to pay for HMRC and Companies House compliance costs!!
Parents should supervise what their minor children look at. Not nanny state.
DS site seems to be back where it was.
Do other readers have complaints about words that were not in the text of a posting. Very odd. After correcting other typos it went through.
Yes, sometimes my comments aren’t uploaded first time because it is said they contain a word that I’ve never used, not once (elided).
Stop talking sense!
The object of Digital ID and age verification is only to do with Government being able to control the citizenry.
Child safety on-line… but not in the towns and cities where they are being raped, or stabbed on the streets by cultural enrichers. So “on-line” safety is baloney.
What exactly is the scale of the “problem” or is it just another confection like “climate change” and “racism” to justify more legislation, limitation of our Rights and freedoms? (Rhetorical.)
Children can see porn on the Internet can they? They used to be able to see it in the school yard and behind the scout hut – probably still can. Danger from on-line pædophiles – isn’t there one behind every lamp post in the streets. What about the recently arrived cultural enrichers loitering outside schools and play areas in parks? Is that not a child safety issue – no apparently it’s Far Right racism.
Herr Vanker et al are very selective about the child protection of which they claim to be so concerned.
Ha! Pass the humbugs mother.
Yes, nice.
Unfortunately barely 15% of MPs have a STEM degree and will have the foggiest idea what you are talking about. And they often seem to be suppressed from any senior roles by the rest – facts, logic, honesty and integrity generally not welcome in politics.
Any system will be abused. Some adults will presumably charge kids a small fee for generating tokens and immediately passing them onto the kid.
Sadly the hopes of freedom and equal power for all on the internet are long gone. The digital age is instead being used by all governments to exert total control over all citizens. The chains of digital control are too light to feel until they are too strong to break.
oh brave new world.
It’s probably not the MPs you should be worried about. It’s the Civil Service who will want to ‘own’ the solution because it will provide jobs, promotions, QUANGOs, and ‘control’ in their own hands rather than relying on others.
Because it’s the Civil Service this attitude will continue no matter which Party is elected to government. Unless Reform or Restore cut this nonsense off at the root.
That’s exactly right.
They might bring back the dog licence.
Barely 15% of our MPs have STEM cells… FTFY
I like the creative thinking.
Not so crazy about the idea of turning the banks into government co-opted nannies even more than they already have.
But don’t have a better solution – other than let parents do their own parenting and everyone else mind their own business, which the “freedom-loving” British public don’t seem to believe in.
They pawned their freedom to the State in 1945 and ever since, in exchange from the cradle-to-the-grave welfare state.
On downloading a recent version of iOS my age was automatically verified by my Apple account linked to a bank card.
So sounds like it can all be done now anyway and the whole “protecting young people” story is just a ruse. Shock.
However a child might use your iOS.
not agreeing with age verification just pointing out the flaw.