Nope they don't. That's the whole point of privacy-preserving age verification.
Technically it is possible. The complaint that people have is that they don't trust that any government will get it right. But it is technically possible with known cryptography.
Ah ok. I understand now. The website isn't making an additional request to the government to verify that the credentials you gave are real. The authenticity is built into the signature.
Yes exactly. With the caveat that an untraceable token can be passed to someone else. So then there are the shady remote attestation schemes that try to make sure that only your smartphone can use that token that was generated for you, and this is very very bad in my opinion.
But if you accept the caveat (like we do for cigarettes, where an adult can buy cigarettes and then give them to a kid), you don't need to remote attestation part.
No, it isn't technically possible. With true anonymity you can also re-sell tokens making them meaningless. If you prevent token sharing then you cannot have real anonymity. You can't have your cake and eat it too.
And if you have to trust the government to get it right then you have already lost because they are definitely motivated to NOT get it right because they WANT to track you.
Technically it is possible. The complaint that people have is that they don't trust that any government will get it right. But it is technically possible with known cryptography.