9 ms·
EU Age Verification Project Mandates Hardware-Bound Attestation
- WhyNotHugo 2mo ago> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux. If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
- Elfener 2mo agoAnd it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers. (and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
- afandian 2mo agoWe need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine. We did it before. We forgot at the time when things were more-or-less free. (I don't know how we do this. I'm as dependent as ever.)
- big85 2mo agoSo much for the EU's mission to reduce e-waste.
- filleokus 2mo agoIf you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement. The key material must be DRM'ed, especially if some ZKP solution is used. Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool. (Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)
- matheusmoreira 2mo ago> If you want to actually enforce age restrictions I don't. This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.
- dwattttt 2mo agoDo you also oppose drivers licensing, alcohol age limits? Those rely on a trusted ID managed by a government.
- matheusmoreira 2mo agoNot exactly a fan of those either, but they're much easier to tolerate because so far they aren't implementing a surveillance state straight out of a cyberpunk dystopia just to prevent kids from driving or drinking. It's not like the car refuses to start if a dad tries to teach his kid how to drive.
- imtringued 2mo agoI have never been asked to show my ID ever in my entire life when buying alcohol. The alcohol age limit equivalent would be to put the entire TPM + proprietary software infrastructure into the cash register, locking in a monopoly on what software can be used on cash registers. Not to mention, you now have to scan your ID, which then obviously gets recorded forever, allowing the government to track your alcohol consumption. Yeah, I'm against that and I don't even drink alcohol, not even the alcohol I've bought myself as a gift to my parents.
- zb3 2mo ago> I don't see how we can avoid the "trusted" hardware requirement. While this is a good point, what's missing here is that this hardware doesn't have to have Google spyware and other bloatware installed. Yet with current design, this becomes mandatory.. security requirements are abused here to force unrelated software on my computer that I have to carry with me in order to participate in society. This app should work on a dedicated device, something like a smartcard with e-ink display.. it would even be more secure because it would have less attack surface. Just like today I'm not complaining about not being able to install linux on my credit/SIM card, I'd not complain about that either. But locking down the whole OS on my smartphone is unacceptable.
- zenoprax 2mo ago> The project’s position is that hardware binding remains required I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store? I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step. Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.
- afandian 2mo agoI don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd. This isn't only a digital sovereignty issue, it's also an anti-competition issue.
- mosura 2mo agoThe EU way is to think these things are “free” and then act surprised by the inevitable consequences five years later when it is irreversible. Our AI gods cannot save us soon enough.
- afandian 2mo agoWhat are the "AI gods" going to do in this scenario? AI is about many things, but a big factor is enclosure.
- petcat 2mo agoThe reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it. The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
- realusername 2mo ago> it is virtually impossible for Europe to even begin to displace Apple or Google devices It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
- inigyou 2mo agoWhat do you expect - the EU to centrally plan a phone OS? They are capitalist with regulations, you know, not communist. Someone has to actually make one themselves. Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share.
- buran77 2mo ago> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
- hellojesus 2mo agoI still contest that I should be able to solder together a basic computer in my garage and communicate with the internet so long as I follow the communication standards. There is never a reason to outlaw general purpose computing.
- buran77 2mo agoA lot of things get deprecated on the internet. You can shout in SSL and nobody will answer back. Tying any solution to specific companies is the major problem. Because even if the rest of the age verification scheme is well thought out in the user's interest, tying it to Apple and Google not only forces people's dependency on foreign private companies, it also invalidates any pretense of privacy.
- 83642736392 2mo ago[flagged]
- dijit 2mo agoIt's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU. What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
- razor-thin 2mo agoI suppose you have a lot of data backing this claim? The head of the EU, Ursula von der Leyen, isn't known to be anti-EU.
- dijit 2mo agoNo head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always. I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022. UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
- mort96 2mo agoA good way to prevent this anti-EU sentiment would've been to not go through with these obviously stupid ideas. Weird that the EU doesn't seem to realize? Or do you think, maybe, that there's a deeper issue here and the problem isn't exclusive to just these anti-EU politicians you want to scapegoat?
- teravor 2mo agonote that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed. usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon). it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device. on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it. also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
- ChrisArchitect 2mo agoRelated: European "age verification" "app" forcing everyone to use Android or iOS https://news.ycombinator.com/item?id=48903777 https://news.ycombinator.com/item?id=48903777 Stop Killing the Internet: No Digital ID and No Age Verification https://news.ycombinator.com/item?id=49084938 https://news.ycombinator.com/item?id=49084938
- userbinator 2mo agoI expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then... ...but then again, this is the EU, not the US.
- izacus 2mo agoHardware attestation literally prevents that. That's why it's mandated.
- userbinator 2mo agoMore precisely tries to prevent, but there have been occasional articles about breaking TPMs here; and I suspect once they become a major obvious barrier to freedom, we're going to see a lot more attacks on them, and more successful ones too.
- izacus 2mo agoPeople have been trying to defeat them for years how.
- big85 2mo agoAll this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist). The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
- jmyeet 2mo agoThat's a completely unhelpful, overly simplistic straw man argument. We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on. So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument. I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal. Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed. At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason. I believe we should shift that liability to advertising.
- xg15 2mo agoWhat you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors. It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
- TacticalCoder 2mo agoBy an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there: https://news.ycombinator.com/item?id=46784572 https://news.ycombinator.com/item?id=46784572 How much do you love your systemd and the individual behind it now? Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you? These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
- xg15 2mo ago> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
- izacus 2mo agoMost countries allow tapping your ID card to a reader device as well.
- SnipeOfficial 2mo ago[flagged]
- 0xfedcafe 2mo agoHere comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.
- intrasight 2mo agoThe article mentions "approved applications". What role, if any, do apps play in age verification if it's implemented in hardware?
- phonkd 2mo ago[dead]
- CommanderData 2mo agoSomeone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea. State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
- deleted 2mo ago[deleted]
- Calamity 2mo agoIndeed, I truly don't understand how simply enabling parental controls onto mobile devices handed to kids which then gets advertised to each website/app that they use isn't sufficient. You make it an opt-in feature to "self-broadcast" that this device is being used by a minor. Solves 99% of the use cases. And for the remaining 1% — the really determined teenager — they'd never be stopped by this anyway. They'd social enginneer their way to access somehow.
- tzs 2mo agoThat's the California approach. Devices whose primary user is a child will have to provide a way for parents to provide an age range for the child, and an API that apps and app stores can use to check that so they can avoid doing things that are supposed to be age restricted. It has been discussed a few times here, and those threads are always full of people proclaiming that it will be the end of free and anonymous internet for all of us and allow tracking everything we do by both the government and any site we visit.
- matheusmoreira 2mo agoThere it is. That's what this "age verification" nonsense was all about. Predictably, the unceasing "think of the kids" rhetoric came down to THIS. Absolute control over people's computers. It's not your computer anymore, it's the government's.
- tzs 2mo agoIt should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability). That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability. Here's the expected timeline. The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#. In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.
- matheusmoreira 2mo ago> It should be noted that this app is temporary. Don't believe that for a second. Nothing is so permanent as a temporary government program.
- pembrook 2mo agoThe concept of an income tax was originally supposed to be temporary.
- throw-the-towel 2mo agoAnd passports too.
- wbl 2mo agoThe hardware security module does not need to change to support tying to a credentials. I showed how to do this years ago and the theory was known long before. Its just that the EU is making self imposed barriers to doing this right.
- phendrenad2 2mo agoThe downvoted comments here are very interesting, and it really shows a divide in beliefs here. I fear that there's no reconciling this, and in the end we'll need two internets: The EUternet and the USternet.
- tavavex 2mo agoThe US is moving in the same general direction, even if they take slightly different measures. The universal tracking of everyone is something all these governments can suddenly agree on. If after this is enacted the firewalls aren't perfect, the internet will probably instead splinter into the Westernet and the everywhere-else-net for the rest of the countries that are too disorganized or uncaring to join in on the fun, maybe with a few safe havens of something resembling the old web in between.
- phendrenad2 2mo agoGovernments are not unified bodies, and attempts to introduce thought control on the internet have failed in the US, but easily passed in the UK. Illinois has recently passed a toothless age verification law and it's being hotly debated, but the UK is arresting people over facebook posts.
- tavavex 2mo agoIt doesn't really matter what is being done, what matters is the trend that countries are moving in. The UK started on a more authoritarian baseline than the US, so their laws are more restrictive. But by and large, everyone is moving in the direction of more control, and there's no reversal in sight. That's not to mention how big the disparity can be between individual US states, many of which are far more extreme than Illinois in anything they do. They don't need universal international cooperation - sufficient cooperation is enough for their goals, and they may get it this time.
- pembrook 2mo agoThis is the most mind blowingly stupid thing I've ever witnessed..and in slow motion...I'm just astonished that the EU is cheerfully walking themselves into destroying the freedoms of their own citizens without much of fight. The most privacy-obsessed people on earth are now handing a detailed log to their entire digital lives over to a group of barely-elected 3rd party overlords as well as foreign companies and intelligence agencies (if you think this won't be instantly compromised, you're tremendously naive). ...AND at the same time this is cementing monopolies for foreign tech companies within Europe. A double whammy of self-harm. There's something very bleak about couching this under the 90s-era "protect the children" narrative too, given ultimately most Europeans care so little about children that they've rapidly stopped giving birth to them and in many countries have outsourced all childcare to the state. It's not even a believable cover story anymore. It seems more like the European officials looked over at the Chinese Communist Party's authoritarian control over the internet and thought to themselves, "Wow, look how little push back they get to their policies online! I want to do big fancy projects with other peoples money and have no accountability or transparency too!"
- Dig1t 2mo agoWhat happens if some social media site hosted in another country becomes popular and refuses to implement these age verification measures? Is the EU going to create a great firewall like China and start blacklisting sites? Are they going to ban VPN’s too? Seems like a slippery slope could easily get extremely invasive and restrictive. It does seem like an effort to connect all online activity to real-world identities.
- hurfdurf 2mo agoIs the EU going to create a great firewall like China and start blacklisting sites Welcome to six years ago: https://diginomica.com/eu-policy-doc-recommends-building-european-internet-firewall-similar-chinas-lets-build-new-digital https://diginomica.com/eu-policy-doc-recommends-building-eur... https://www.europarl.europa.eu/RegData/etudes/STUD/2020/648784/IPOL_STU(2020)648784_EN.pdf https://www.europarl.europa.eu/RegData/etudes/STUD/2020/6487... "Like the Chinese firewall, this European internet would block off services that condone or support unlawful conduct from third party countries." Sound familiar?
- user00005 2mo agoI searched this page for 'fascist', 'fascism', 'far left', and 'liberal' and there were no results. A surprising little amount of criticism considering the rhetoric in any political right adjacent threads on this website. There are three mentions of 'trump'.
- Saline9515 2mo agoThis is neither a far-left, far-right or centrist measure. It's a pure technocratic one, where the State and its minions believes optimize for control over the population, and matters like "privacy" or "resilience" don't appear in the cost function.
- freefaler 2mo agoCory Doctorow had a very profound talk about it very long time ago (10+years). https://www.youtube.com/watch?v=HUEvRyemKSg https://www.youtube.com/watch?v=HUEvRyemKSg As the internet become the place where people do a lot of things, no government (and especially no security services) will be able to keep themselves from trying to control it or at least monitor it. And with the new LLM features they can automatically do much more than before. Human nature is a constant and when the government sees an easy way to enforce something, many more bureaucrats will try to do it.
- dumberquestions 2mo agoI predict that teenagers with irresponsible parents will continue to use social media and online anonymity will get worse.
- jocelyner 2mo ago[dead]
- PeterStuer 2mo agoWhat is the authority of the "repository maintainer" in question? It feels descisions like these far outstrip the pure technical.
- Grimeton 2mo agoX509 is all you need.
- euroderf 2mo agoHow about a grand trade: Age verification for Corporation ownership verification. - No more shell companies. - Only humans may own shares. - Public ownership registers. Know thine enemy.
- MetroWind 2mo agoWhat a shit show lmao. Problem: corporations pushing harmful ads and arranging social media timeline in harmful ways to kids Solution: restricting the individuals. Giving corporations more control. Giving people less choice. Yeah makes sense.
- leawi 2mo agoLook, I appreciate the article, I believe these are important news worth discussing, but was there really no way to write it without LLMs? I'm sure there are enough proponents of "what's important is the content, not who and how exactly typed it," but my brain has developed something like ad banner blindness but for LLM writing - it just shuts off as soon as it sees "this distinction matters" or "does not automatically guarantee." This is not to mention that LLM generated texts are just really confusing and difficult to read, take for example this sentence: > Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. At least two people here agreed it's a really weird way to put this, but at this point I'm honestly inclined to believe that this is just the product of AI putting together some words that kind of sound on-topic even though they are actually meaningless in the context (a.k.a. AI slop), and not someone's actual thought. --- 100% AI pangram: https://www.pangram.com/history/8c60b6ec-cd89-41fb-b8c8-abc096973f47 https://www.pangram.com/history/8c60b6ec-cd89-41fb-b8c8-abc0...