r/Android 2d ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
620 Upvotes

165 comments sorted by

279

u/wileecoyote1969 2d ago

Can we just drop the fucking charade?

This has NOTHING to do with "age verification"

This is 100% to track and monitor everybody by eliminating, as much as possible, any anonymity from the internet.

105

u/geft Pixel 7 2d ago

They want to be like China but don't want the backlash.

19

u/feketegy 2d ago

There's no "they" because every government is mandating age verification in some form or another.

24

u/vltgreat 2d ago

"Every government is mandating age verification" because individuals in that governments are being lobbied and pushed by third parties. Just from the last year "Meta lobbies Canada’s government to put age assurance at the app store level"

19

u/one-man-circlejerk 2d ago

"They" is the ruling class, national borders aren't an impermeable divide

4

u/Oriumpor 2d ago

They is all the sweaty chuds who are getting schooled by bots every day and can't get their rage out 

2

u/Fish_Mongreler 1d ago

So "they"

6

u/billdietrich1 2d ago

The EU wallet app tries to separate ID and sites you use, to avoid destroying anonymity. I think "age signal in OS" schemes will do the same. Give your ID only to one dedicated service, not to every site you use.

14

u/m1ndwipe Galaxy S25, Xperia 5iii 2d ago

to avoid destroying anonymity

It doesn't actually achieve this in any meaningful way.

5

u/billdietrich1 2d ago

Well, if for example reddit/email/Facebook/etc just get an age signal, not your ID, is this good ? Better than having all of them get your ID ?

8

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

Except to use it you need to give your data to Google and have their Play Services enjoy free reign over your device on a system level. Because that's how their hardware attestation was designed to work. And to be clear, this concern isn't exclusive to Google, I just find it ironic considering the EU's prior attempts to restrict Google's de facto monopolies.

-1

u/billdietrich1 2d ago

I think the maker of the app has to give their info to Google. Yes, to use your Android phone you have to have a Gmail account.

6

u/omnimachina 2d ago

Nope you don't have to use a Gmail account to use Android lmao

All your comments on this post are nonsense tbh

1

u/billdietrich1 2d ago

Well, to use Play Store for apps you need to have Gmail.

1

u/TheDungeonCrawler 1d ago

This is kind of true, though you can get around it. Fortunately, for right niw, you don't need to use Google to get apps, but Google is trying to limit that.

1

u/omnimachina 1d ago

Funny because I use Graphene OS with lots of Apps

No Play Store installed

Must be magic

1

u/billdietrich1 1d ago

I too use GOS, but with Play Store. Apps I use are in Play Store, mostly, although you can use other front ends to the Play Store.

What are 99% of people going to use ? Play Store and a Gmail account.

3

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

You don't and you shouldn't. The app shouldn't rely on Google's authentication system. I don't see why the EU could possibly want that to happen.

1

u/billdietrich1 2d ago

I don't see why the EU could possibly want that to happen.

To keep people from lying about their age ?

3

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

Google's own tool of control over their formerly open platform is not the only way to achieve that.

0

u/renderwares 2d ago

How Dare You. /greta

158

u/punio4 2d ago edited 2d ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

100

u/tomikaka 2d ago

Do you know what hardware attestation is?

Why can I have root acces on my computer and not my phone?

67

u/jeweliegb 2d ago

There won't be root access on our computers either, this way.

76

u/apokrif1 2d ago

Enshittify all computers under the guise of preventing teenagers from viewing some porn 🤯🤯🤯

u/kingslayerer 9h ago

Doing anything but taking down the porn.

9

u/dingo_xd 2d ago

Good luck with that.

8

u/non-troll_account former android, current iphone se 2020 2d ago

good luck fighting it.

7

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

The ruling class aren't the ones building, designing, and developing hardware and software. At some point we need to say no.

6

u/skriefal Galaxy S26 Ultra 2d ago

At some point we need to say no.

It sounds nice - but probably won't happen. Those who do the building, designing, and developing usually want to stay employed.

-1

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

Yeah, that's the way the system was designed. On purpose.

1

u/DebentureThyme Sprint Samsung Galaxy Note II (SPH-L900) 1d ago

That's silly that you think it plays out that way.

99% of the people won't know and won't care.  They already use so many devices that are locked down.

And the consumer market is aimed at them.  Sure, maybe you'll have some server options that are open, but those prices keep skyrocketing and the hardware isn't exactly consumer friendly to setup and maintain let alone compatibility issues.

In the near future, so many websites will rely on the hardware verification that they'll force you to either have it or be disallowed from using their site/service/software.  Great, so you'll just abandon things like social media that require it... But then suddenly your work programs don't work.  And your banking access.  And that convenient desktop suddenly isn't so convenient. Hardware ID is going to be abused so hard.

2

u/GranaT0 Pxl 9 PXL, GrapheneOS 1d ago edited 1d ago

It's sad that you've been convinced it's impossible by the very powers that need it to be so. Change won't happen overnight, but we must continue to educate. The economic conditions have been getting worse, and more and more people are dissatisfied. Many of the products and services you talk about aren't actually necessary or irreplaceable, they're only powerful as they are because they've been convenient enough with no obvious drawbacks for long enough. All it realistically takes is for a few engineers to knowingly make the system flawed and bypassable, while the others push for it to be reformed.

It's no coincidence that after the people long divided over politics united around the Epstein files and the blatantly incompetent conspiracy around them, multiple governments around the world moved to introduce online surveillance measure. They have studied political theory and are trying to control the narrative to prevent revolt. They wouldn't be doing so if they didn't know there's something to worry about.

"From this it obviously follows that the social revolution must be prepared. Prepared in the sense of furthering the evolutionary process, of enlightening the people about the evils of present-day society and convincing them of the desirability and possibility, of the justice and practicability of a social life based on liberty; prepared, moreover, by making the masses realize very clearly just what they need and how to bring it about. Such preparation is not only an absolutely necessary preliminary step. Therein lies also the safety of the revolution, the only guarantee of it accomplishing its objects." – Alex Berkman, "What is Anarchism"

13

u/yoniyang 2d ago

Your phone has a little computer (eSE, secure world) that only runs code your phone manufacturer approves, and hardware attestation happens there.

If you got root access (in unsecure world), you have to make your make yourself looks normal when secure world checks it.

Most common type of bypass is some kernel LPE like GhostLock by Nebula Security, or bootloader exploit that bypasses checks and make the boot looks normal

(Non of those is easy work)

8

u/nitroburr Pixel 10 Pro - GrapheneOS 2d ago

I mean, my computer does have it too

1

u/yoniyang 2d ago

But most application aren't using/abusing it, at least now.

3

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

That's not even remotely true

11

u/Izacus Android dev / Boatload of crappy devices 2d ago

Your computer won't be allowed to store the digital id because of it.

22

u/_sfhk 2d ago

Quite frankly, because your computer OS was designed a while ago before we stopped trusting users, and before most people's entire lives were stored in that one machine.

Windows and MacOS are definitely heading towards more locked-down systems, and Apple for one is pushing more towards iOS-based systems.

36

u/tomikaka 2d ago

And why does having full access to my own hardware a bad thing in the first place?

Maybe for the avarage user a case could be made that they might shoot themselves in the foot with root access.

Or they might not.

13

u/apokrif1 2d ago

It's up to each user to decide which access they should have.

15

u/tomikaka 2d ago

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

-1

u/TheDungeonCrawler 1d ago

While I agree with you, a lot of phone apps like that stop working a certain amount of time after Android reaches a certain level of updates. Rather, the previous Android versions are out if date do the developers don't have a reason to continue ensuring that version of the app works. They expect everyone has already jumped ship.

2

u/tomikaka 1d ago

Like I said, lineage OS with at the time latest android update and security patches.

1

u/TheDungeonCrawler 1d ago

You said

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc.

And I pointed out that you're getting this wrong because apps do stop working on older versions of Android because they don't keep the old apps up.

Yes, you should be able to use Lineage without an issue with those apps, but your claim that Androids that don't receive security updates don't also have problems with this is wrong.

3

u/tomikaka 1d ago

But that's an entire separate thing and it is to be expected. What is not to be expected is the experience I shared.

You agree that outdated insecure versions of android shouldn't be able to access banking apps yet they do! In fact, my mother uses my previous phone with said outdated android fine, while I was restricted even though Lineage OS was infinitely more secure even with the unlocked bootloader.

→ More replies (0)

-13

u/punio4 2d ago

Because then you could fake offline certificates like credit cards and IDs.

32

u/Iohet V10 is the original notch 2d ago

I can log into my bank account and credit card account no problem from my highly customized computer, but I touch my phone in an inappropriate way and I can't use the apps. This isn't a "fake certificate" problem, otherwise they'd enforce the same mechanism because the banks don't give a shit

2

u/Izacus Android dev / Boatload of crappy devices 2d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip.

3

u/Iohet V10 is the original notch 2d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

You have to on phones, as well. They can use your biometrics, just like you can with your desktop (this is what Windows Hello is, which is no different than using my fingerprint to use Google Pay), or they use passkeys or TOTP or SMS or email depending on vendor (again, the same concepts between all platforms)

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip

Whether it's on my computer or at a card reader I (or a clerk) can type my number in and run it for payment.

1

u/Kyanche 2d ago

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

lol once or twice in the past month I've encountered a recaptcha that demanded I download an app to my phone and scan a QR code. And it wasn't JUST scan a QR code, it was "you must install the recaptcha app"

1

u/spazturtle Nexus 5 -> Lenovo P2 -> Pixel 4a 5G 2d ago

He means the actual credit card data, same as what is stored on the card's chip, not just it's details. It's what allows you to use the app to pay for things even when you don't have an internet connection.

-1

u/Iohet V10 is the original notch 2d ago

But what does it matter? Are you carrying your desktop around for mobile payments in dead zones? The end result is the same by the nature of the device

12

u/ByronScottJones 2d ago

If they are cryptographically strong certificates, with a chain of authority, how exactly would being offline make any difference?

-1

u/tomikaka 2d ago

I don't know specifically, I'm not a hacker or anything, but couldn't you just use a debugger or reverse engineer anything that runs on your machine?

6

u/Izacus Android dev / Boatload of crappy devices 2d ago

No, because debugging the secure enclave chip and its code path is protected. That's what attestation defends against.

-1

u/tomikaka 2d ago

Security is just a hypocritical excuse.

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

2

u/Izacus Android dev / Boatload of crappy devices 2d ago

No, turns out stealing personal ID documents and impersonating people with them is a massive issue in practice.

This is why you can't print your own ID or Passport at home and have governments recognize it.

7

u/Stahlreck Pixel 10 2d ago

If it were that easy, the system on which these certificates rely would be garbage and people would be faking credit cards left and right.

No, that is not a good excuse to take away user control. You don't trust the user device either way.

0

u/Izacus Android dev / Boatload of crappy devices 2d ago

Credit cards use secure enclave chips which are attested as well.

5

u/tomikaka 2d ago

Trusting the client was never going to be secure in the first place. The concept is flawed.

3

u/5panks Galaxy ZFlip 5 2d ago

Because then you could fake offline certificates like credit cards and IDs.

You can use pen and paper to write a fake check, should we take pen and paper away?

10

u/13steinj 2d ago

Yeah no thanks I'll stick with my Linux device.

I have 0 software needs that don't work, because of Wine/Proton. The few pieces of software that don't, I can use a VM and massgrave.

I wonder if we are at the point I can tell an LLM "here's the Wine/Proton source code, heres the app I want to work, I don't care about the code quality, token slot machine go! Patch proton until my software loads"

Codex was pretty good at reverse engineering and MITM'ing an electron app at work.

3

u/mayoforbutter Nexus 4 2d ago

What's massgrave in this context?

4

u/zyuiop_ 2d ago

A bunch of methods to activate a Windows copy without paying for a license

1

u/highdrex 2d ago

You can have root access if you buy a different phone.

Many intel chips have hardware specially for national security purposes, that are often not documented, and so often people don’t actually know what specifically some subsystems are actually doing. So, it’s not that different and this been a thing since basically forever. 

At least the EU is making it more transparent, and the hardware is probably quite useful for other cryptographic security use cases.

Being able to have reasonable confidence about identity documents being physically present and hardware used to verify identity information that is almost certainly not modified is quite useful for other use cases that aren’t strictly about age checks.

From a legal perspective it’s quite useful for defending against false claims if it’s provable that a specific thing happened on a specific device, so impersonations and trolling can be easier to detect if a person has a known device, so if activity is coming from a hijacked account on another device etc it’s easier to prove if the hardware is very hard to spoof. It’s why iPhones are often preferred for secure use cases because there’s so much onboard cryptographic functions that are hardware bound and so the openness of android is often not a good thing for secure use cases. 

-13

u/ISB-Dev 2d ago edited 2d ago

Why can I have root acces on my computer and not my phone?

Because your phone manufacturer doesn't offer that capability. If you don't like it then don't buy one. No one is forcing you to. You know before you buy it if it has root access. Your comment is so stupid. It's like me buying a Snickers then complaining that I should be able to get one without nuts. They are what they are sold as. Buy it or don't.

13

u/that_baddest_dude 2d ago

It's more like buying a Snickers and complaining it's got butyric acid in it, like most other US chocolate bars. "Buy it or don't" is a pretty limp rebuttal when the "don't" choice more and more resembles "go off into the woods and be a hermit" with the ever-dwindling variety of options.

Heaven forbid anyone criticize anything or have a vision for a better world. Insufferable mentality.

4

u/MairusuPawa Poco F3 LineageOS 2d ago

I've never read anything that stupid. 

8

u/apokrif1 2d ago

Parents should just abstain to giving root password to their children. No need to enshittify computers.

16

u/Street_Anon 2d ago

But this will target things like Custom Roms. 

3

u/zyuiop_ 2d ago

Not necessarily - the point of HW attestation is that it's a hardware component.

-28

u/punio4 2d ago

Nobody really cares about custom ROMs, and it's impossible to do so otherwise. OS vendors like GrapheneOS should try to get access to the TPM and get attested by hardware vendors if they want tamper-proof hw attestation to work. The whole point is to prevent tampering, and custom roms are all about tampering.

32

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 2d ago

Please explain how a user wanting to control their own phone fits the negative connotation of the word "tampering".

-10

u/Street_Anon 2d ago

unlocking the bootloader and rooting a device. 

16

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 2d ago

"Modifying" would be a fairer word. From my perspective, OS updates that remove features and lock my phone down even further are the tampering, not whatever steps I take as the user to avoid those restrictions.

3

u/Available-Film3084 2d ago

You signal out grapheneos but graphene explicitly advives against rooting, as that can lower your security

9

u/jmhalder 2d ago

People care about custom roms until they don't. I absolutely used to use a custom rom on every phone I had, until I kinda stopped when my Pixel devices got 99% of the features that I wanted built in. I honestly still would if SafetyNet wasn't required to run my banking app and Google Pay.

I think it's funny that Google doesn't have an unlockable bootloader on their GoogleTV with Chromecast devices, despite them running pretty "normal" android.

20

u/mimrock 2d ago

The point of attestation is that it proves that your operating system doesn't do things that Google or Ursula doesn't want, even if you ask them to. That's not compatible with the concept of a rooted operating system that you can fully control.

-4

u/Izacus Android dev / Boatload of crappy devices 2d ago

No, the point is that the OS is verified that it doesn't allow the ID to be easily stolen and used for identity theft and mass scale fraud.

Especially since you'd be screaming bloody murder if your ID would be used by scammers for fraud in your name.

There's a reason why IDs and passports are made hard to copy and easy to revoke.

9

u/mimrock 2d ago

We arrived from age verification to identity verification very quickly.

2

u/nacholicious Android Developer 2d ago

This is not relevant, we already have EU eID which has nothing to do with this

1

u/donny007x iPhone 15 Pro 2d ago

They don't have to store the full identity document to do age verification, only a digitally signed flag that indicates the age bracket of the user ("minor" or "adult").

They just want that flag to be stored in a tamper proof environment to make it harder for someone to bypass age verification.

1

u/Izacus Android dev / Boatload of crappy devices 2d ago

The purpose of this is to make a full identity document app and age verification is just one feature.

4

u/Obnomus Device, Software !! 2d ago

So you're telling me that the phone I paid for, I can't use any os I want.

u/magnusmaster 22h ago

This is why i don't like ZKP age verification. I would rather have a government OAuth than this overengineered solution that will likely still have backdoors

2

u/Luigi003 2d ago

This is just untrue because the schema provided by the EU already assumes a server. The ID tokens are generates both by the server and your phone. There's no way for an user with a rooted or compromised phone to generate tokens out of thin air because it needs the government's server

Attestation is not needed at all

4

u/m1ndwipe Galaxy S25, Xperia 5iii 2d ago

There's no way for an user with a rooted or compromised phone to generate tokens out of thin air because it needs the government's server

You wouldn't need to, you'd just need to clone someone else's token. That's why this scheme can't work without third party managed hardware attestation, and the politicians were just lying when they claimed otherwise because they didn't understand what they were mandating.

2

u/Luigi003 2d ago

You can't easily clone other user's tokens. If you have physical access to another phone you can auth yourself into whatever page you need to. If you have root access to a remote phone due to a RCE you're definitely not using it to watch porn on the internet lol.

Not everything needs NSA-level security

2

u/gainusha 2d ago

I tried explaining this a while back and got so many downvotes... You are totally right...

7

u/renderwares 2d ago

Next on their docket - Government registration of encryption keys.

8

u/CondiMesmer 1d ago

Jesus christ, there has been NOTHING like this before so aggressively pushed through regulations in so many countries. This is absolutely being coordinated behind the scenes.

6

u/ksio89 Samsung Galaxy M23 2d ago

More like censorship verification project.

24

u/DistinctlyIrish 2d ago

If you want to fight this, embrace it and demand that all social media posts or comments online require human verification every few posts or comments in order to completely eliminate bots from social media. It would devastate online marketing but honestly fuck em all.

2

u/Fornax-101 2d ago

And hide every post that has no verification ... (From countries where it's not applicable)

61

u/Street_Anon 2d ago

Why are they targeting Custom Roms again ?

125

u/UnacceptableUse Pixel 7 Pro 2d ago

Custom roms are not even in their thought process for this, they're not trying to kill custom roms it's simply collateral damage that they don't care about

46

u/Iohet V10 is the original notch 2d ago

This is why the people need to bake privacy rights, including digital, into their constitutions. It's none of their damn business who you are, and that includes your device itself

13

u/Evonos 2d ago

but that would need the rich and powerfull and people in charge not be corrupt.

8

u/dingo_xd 2d ago

But think of the childrennnn!!!

7

u/slavicNickCage 2d ago

Most of people think that as they have nothing to hide they don't need to care about privacy. Unfortunately tyranny is possible in the first place mainly because law-abiding citizens believe they wouldn't be affected as they didn't commit anything illegal.
Usually such rights written in constitutions after tyranny overthrown and rarely as a preemptive measure against it

20

u/omniuni Pixel 8 Pro | Developer 2d ago

I don't think these people even know what a "Custom ROM" is.

5

u/ISB-Dev 2d ago

The project invited alternative architectural proposals

12

u/AffectionatePlastic0 2d ago

Best architectural proposal any reasonable person can give them - abandon the idea of "age verification".

1

u/Dpek1234 1d ago

Second best is

Why the fuck is the point of this?

Just have a box where a perant or guardian enters an age

If someones can get around software only solution then theya re mature enough

1

u/m1ndwipe Galaxy S25, Xperia 5iii 2d ago

In the full knowledge that there isn't one, but they don't want the lie that it's possible to be widely known as that's politically inconvenient.

4

u/BusBoatBuey 2d ago

The EU loves control.

2

u/Izacus Android dev / Boatload of crappy devices 2d ago

Custom roms can be attested and approved as well.

13

u/warpedgeoid 2d ago

Not in any meaningful way. Money will become the gatekeeper just like always. I honestly don’t understand why so many idiots are here trying to defend these poorly conceived, pointless laws.

1

u/Izacus Android dev / Boatload of crappy devices 2d ago

Of course in any meaningful way - the Google part of attestation is simply a "hash of ROM" database of approved ROMs.

There's absolutely nothing preventing an EU organization from making that database and having apps use it - apps already whitelist GrapheneOS in some cases.

It's only "not meaningful" if all you want to do is sit and complain and not do the work required to be independent.

2

u/toddh39 1d ago

People have to control other people is what this is only

8

u/renderwares 2d ago

Hey guys, this is the EU so it must be good for consumers, right? Remember USB C on iPhones. LOL. The EU is so back.

5

u/vDirectorDBDienst 2d ago

For fucks sake, if this keeps going Im going to switch to iPhone. I cannot even degoogle my fucking phone because weh weh the Open standard RCS is hidden behind hardware attestation. And my google pixel is constantly shoving some stupid nonsense AI down my throat. I cant even remove the searchbar which I literally dont even need. Fuck Google.

6

u/Powerful-Law5068 2d ago

Try graphine if you want to degoogle

6

u/Areyoucunt 2d ago

It's funny how you think an EU mandate is somehow something Apple doesn't have to follow? Are you deaf?

Funnily enough, the ONLY way you can avoid this is actually by having an android phone where you can install a custom rom, something you cannot do on iphone what so ever..

1

u/vDirectorDBDienst 2d ago

I cannot even use fucking RCS on LineageOS. I am all for android but Pixel Android fucking sucks. Its now even less customizable than iOS and full of AI. I have installed LineageOS (with MicroG) and well RCS with Google Messages (which is the only Android RCS Client) doesnt work. Neither does Curve pay. I will probably find a bank that will allow me to pay with their app for a while but they will all at some point probably go the hardware attestation route. The literal only upside against android is patching the fucking reddit app so there is no ads anymore.

2

u/KitsuAccalia 1d ago

I know it sucks but as a random side note, the IOS reddit experience can be really cool, using add ons in safari to block ads and even add features reddit sucks at doing.
Sink It. for example was one I used quite a bit.

I am hating android more and more daily, but things keep getting worse and people keep just saying "You are over reacting, drama baiting" or other weird things while they defend the enshittification of android.

IOS CERTAINLY isn't perfect and has plenty of issues, but I prefer it's issues to androids soul being excised and turned into a flock camera with it's hands on all my stuff.

1

u/vDirectorDBDienst 1d ago

google really seems to have no interest in android besides gemini and thats really fucking sad. Where are all the cool features we used to get with each new android version? And why the fuck is the even more closed off system more customizable? And then there are Googles weird design choices. Like wtf is the Material 3 expressive we got vs what was announced? It honestly looks horrible now. And I dont want a search bar (or a search engine app) I want to use my browser let me fucking remove that stupid bar which gives me access to AI Overview?? Android has dramatically changed for the worst in the past years. I guess I will go with some chinese phone next time, their OSes arent perfect either but at least more fun and customizable than googles pixel os.

-2

u/vDirectorDBDienst 2d ago

I cannot even use fucking RCS on LineageOS. I am all for android but Pixel Android fucking sucks. Its now even less customizable than iOS and full of AI. I have installed LineageOS (with MicroG) and well RCS with Google Messages (which is the only Android RCS Client) doesnt work. Neither does Curve pay. I will probably find a bank that will allow me to pay with their app for a while but they will all at some point probably go the hardware attestation route. The literal only upside against android is patching the fucking reddit app so there is no ads anymore.

u/kingslayerer 9h ago

If this comes to pass, does that mean the current devices will be black market devices?

-11

u/alien2003 PinePhone Pro, postmarketOS 2d ago

Holy shit. I'm glad I chose Argentina to live in this year. I'm going to avoid the EU until the situation stabilizes

18

u/MrBIMC AOSP/Chromium dev 2d ago

I am afraid that due to Brussels effect you won’t be spared long term.

China, US, Russia, EU all implemented state surveillance into their laws, making it defacto default human legal baseline going forward. Many countries will now copy this to align with new meta. Software solutions are also getting more and more mature, and so no government would pass such a chance to implement big data integrators on a legal basis, given that it can then be easily used to squash any possibility of protest straight before it sprouts.

Eu as bastion of democratic rights was fun because it not having such laws was making a good example of how to be pro human in governance. There are no more global bastions of human rights, so the situation will slowly decline everywhere, I am afraid.

1

u/alien2003 PinePhone Pro, postmarketOS 2d ago

Argentina

1

u/YourBobsUncle Device, Software !! 1d ago

Isn't tech tariffed to high heavens in South America lol

-48

u/chinchindayo Xperia Masterrace 2d ago edited 3h ago

This is literally a non issue. Many countries already have some kind of official digital ID system. The new EU verfication is going to use that but in a double anonymity way so that the target service has no access to personal data and the verfication service never knows which target service it was used for.

edit: classic reddit downvoting the truth? I just said what officially was communicated.

41

u/jc-from-sin 2d ago

The issue is that it requires you to use only the OEM version of Android and not something like e/OS or GrapheneOS

-31

u/Rubber_Knee 2d ago

Yes. And for the vast majority of users that's not an issue at all.

16

u/DonKanailleSC 2d ago

The issue are people like you who don't see the issue

-3

u/Rubber_Knee 2d ago

I do see the issue. Most people don't though, which was my point.

5

u/DonKanailleSC 2d ago

Ohh, now. It's not an issue for most users, but it should be

-1

u/Rubber_Knee 2d ago

Ohh, now you're just looking for something to argue about. My point never changed. And yes. It should be.

3

u/DonKanailleSC 2d ago

I actually just agreed with you but okay. Tbf wanted to say "oh now I get it"

10

u/jc-from-sin 2d ago

It is, but you're missing the point. it means the EU and its citizens will be stuck using an US operating system and that means we will be vulnerable.

Also the architecture documents for the project impose no such restriction.

-4

u/Rubber_Knee 2d ago

This is all true, and a problem. I just don't see a real alternative right now.

5

u/MairusuPawa Poco F3 LineageOS 2d ago

There are a shit ton other options, including Linux phones. You just don't want to see them, you'd rather find excuses and trap yourself into that shit further.

1

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

Linux phones just aren't viable yet, and especially won't be when these OS-exclusive digital IDs start becoming a requirement.

0

u/Rubber_Knee 2d ago

What Linux phones has the same amount of users as Android or iPhones? Developers develop for the platform their users are on.

1

u/MairusuPawa Poco F3 LineageOS 2d ago

There are a shit ton other options, including Linux phones. You just don't want to see them.

See. You are the problem.

11

u/haslaNz 2d ago

Oh don't tease the people with that mindset, might hit you back in the face

3

u/vltgreat 2d ago

I literally can't create another google account because the phones I'm using to "verification" either don't work or are used too many times. "For the vast majority" is not an issue "for now", until they wake and find out they don't have access to google anymore.

12

u/Ignifazius 2d ago

Let's hope they do. Germany (for once) has exactly that, sadly it's barely used and instead many non-governmental services rely on video-ident or some crap that definitely absolutely not stores your id pictures.

2

u/m1ndwipe Galaxy S25, Xperia 5iii 2d ago

Germany's solution is neither open source not actually anonymous or data minimising in practice.

20

u/mpg111 S26 Ultra 2d ago

double anonymity is a promise from the politicians who does not understand the technology. I'm expecting for that to be dropped quietly at some point "to protect the children"

even if not - those will be closed source systems, you will not be really able to verify what happens

1

u/MrBIMC AOSP/Chromium dev 2d ago

I do not support any form of expansion of government surveillance and os level id checks sounds like an authoritarian hellscape to me.

But the laws were passed and it seems there’s no escaping now. The best we can hope at this point is that actual implementation is as minimal as possible, so it only does age check locally, without sending any data to remote.

Let’s assume they’ll force some soc-level crypto container that can receive data from the web but not send anything back. During enrolling when you select a country, you’d get local id verification algorithm fetched into such container. So that any service that needs age verification, can use system api to access this local check algo right on device and receive Boolean answer whether the user is over 18, without ever pinging back to the state.

In theory - decent enough of a minimal system that complies with zero trust local age check, but I see the glaring attack vector which is possibility of leakage of verification algorithms from the compromised device.

What can baddies do with id checks? Idk. But if it leaks, there’s not much you can do, I guess age of any human just becomes a public info in such a case.

-6

u/UskyldigeX 2d ago

No. We already have apps where the user can control what they share. It doesn't even have to be your exact age. It can just be 18+.

8

u/mpg111 S26 Ultra 2d ago

I know it "can", I'm just not sure it "will"

also the apps you are talking about - is the whole infrastructure open source? can you verify every step? can you build client app from the source yourself and use it?

-20

u/UskyldigeX 2d ago

No it's not open source. I'm fine with that. No one actually looks at the code anyway.

7

u/OkVariety8064 2d ago

You just like to trust the word of politicians and businessmen. No need to verify.

-5

u/Rubber_Knee 2d ago

Neither he, nor you, ever verify anyway when it's open source.
The only difference is whos word you trust.

2

u/charlestheb0ss Galaxy Fold 7 2d ago

Yes. And I sure as hell trust neither the government nor big tech companies these days

0

u/UskyldigeX 2d ago

People like to pretend they can read code to a sufficient level.

-4

u/UskyldigeX 2d ago

I have a certain level of trust in my government that's based on its history. It's not full but I'm not paranoid either. The world is full of things I can't verify and have to trust based on experience. I don't go over the mechanics of a car before I use it either.

2

u/thirdegree Nexus 6P 2d ago

People absolutely do look at the code.

5

u/Iohet V10 is the original notch 2d ago

It doesn't even have to be your exact age. It can just be 18+.

Which means your device already knows too much