When we hear about “zero knowledge” ID checks in real proposals they’re not actually zero knowledge altogether. They have built in limits or authorities to prevent these obvious attacks, like requiring them to interact with government servers and then pinky promising that those government servers won’t log your requests.
In a true zero-knowledge system sharing falsely shared credentials becomes easy because it’s untraceable. If the proof has no knowledge attached, you can’t conclude who used their credentials on a website that generates proof-of-age tokens on demand for visitors.
(Note, this is why they won’t stop at the CA bill.)
Its billions of lobbying for state surveillance under a smokescreen you bypass with basic human interaction.