HN loves cloudflare. The majority here aren’t of the ethos of the distributed internet of days of old, it’s the “how can I monetise this hustle” ethos. Sad really.
They key would be hashed with the user’s details (ip address, value in a session cookie etc) so someone else can’t reuse it. Hell there are things like elliptic curves and DH which still seem magic to me.
Now sure if the identity provider and the site work together they could negate the anonymity, but given that for the identity provider anonymisation would be the key selling feature they wouldn’t want to risk that. Mullvad I’m sure would be trustworthy enough.
I have no doubt China would offer a far better location somewhere like Shanghai. The intelligence benefits of so many foreign diplomats and spies walking your street, drinking in your bars, paying your hookers, is incalculable.
Doesn’t really matter surely, you only need to trust the identity provider not to leak your identity and your porn provider not to have a key that your identity provider can link to.
> but that’s way beyond the technical capability of probably 95% of people.
It really isn’t, and even if it were an ISP could offer it. Indeed I believe most ISPs do (I chose one which is unfiltered, I do my own filtering at a router and dns level, the biggest threat is DoH)