Doing a brief search, it's a KYC system done via smart contract that doesn't store sensitive data like personal IDs or passports on company or third-party servers, which could be leaked. This is better than the current mandatory arrangement. The problem is that governments don't accept this arrangement and want to impose what they think is correct.
Exactly, the technology is there, but unfortunately governments around the world is sticking with the most unsafe, traditional way of KYC verification and the fact that most KYC verification being handled by 3rd party is asking to get the data leaked.
If only they want to invest a little bit of money to upgrade the KYC verification to a better one, we'd be having significantly less wrench attack and there is no more KYC leak.
A zero knowledge solution would be significantly better than what we have now. A better idea would be to do away with it altogether since it has never been an effective way to prevent crime. I know that’s unlikely to happen, but I would at least like to not be asked to scan my face and upload a picture of my passport to buy a $15 gift card. There are even more absurd examples where you must agree to a complete privacy invasion to access certain websites or products.
Buying $0.75 worth of Telegram stars on the Fragments marketplace, that requires KYC too. I don’t see how this is beneficial in any sort of way for the amount of damage that might come as a result of a data breach or rogue employee.
One weak point that ZK-KYC have is the fact that it still require us to verify ourselves even though only for once, after that we can simply verify ourselves without the need to reveal important data that can be leaked.
I think it's a solid compromise and good enough middle ground but I'm sure not the one that the government want to do. I agree though, KYC has never been effective but government would still require it regardless.