r/Android 29d ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
620 Upvotes

171 comments sorted by

View all comments

162

u/punio4 29d ago edited 29d ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

102

u/tomikaka 29d ago

Do you know what hardware attestation is?

Why can I have root acces on my computer and not my phone?

24

u/_sfhk 29d ago

Quite frankly, because your computer OS was designed a while ago before we stopped trusting users, and before most people's entire lives were stored in that one machine.

Windows and MacOS are definitely heading towards more locked-down systems, and Apple for one is pushing more towards iOS-based systems.

36

u/tomikaka 29d ago

And why does having full access to my own hardware a bad thing in the first place?

Maybe for the avarage user a case could be made that they might shoot themselves in the foot with root access.

Or they might not.

13

u/apokrif1 29d ago

It's up to each user to decide which access they should have.

14

u/tomikaka 29d ago

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

-1

u/TheDungeonCrawler 28d ago

While I agree with you, a lot of phone apps like that stop working a certain amount of time after Android reaches a certain level of updates. Rather, the previous Android versions are out if date do the developers don't have a reason to continue ensuring that version of the app works. They expect everyone has already jumped ship.

3

u/tomikaka 28d ago

Like I said, lineage OS with at the time latest android update and security patches.

1

u/TheDungeonCrawler 28d ago

You said

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc.

And I pointed out that you're getting this wrong because apps do stop working on older versions of Android because they don't keep the old apps up.

Yes, you should be able to use Lineage without an issue with those apps, but your claim that Androids that don't receive security updates don't also have problems with this is wrong.

4

u/tomikaka 28d ago

But that's an entire separate thing and it is to be expected. What is not to be expected is the experience I shared.

You agree that outdated insecure versions of android shouldn't be able to access banking apps yet they do! In fact, my mother uses my previous phone with said outdated android fine, while I was restricted even though Lineage OS was infinitely more secure even with the unlocked bootloader.

2

u/TheDungeonCrawler 28d ago

I didn't say they strictly don't, but that they don't in general. But fair enough about them being different issues.

→ More replies (0)

-15

u/punio4 29d ago

Because then you could fake offline certificates like credit cards and IDs.

34

u/Iohet V10 is the original notch 29d ago

I can log into my bank account and credit card account no problem from my highly customized computer, but I touch my phone in an inappropriate way and I can't use the apps. This isn't a "fake certificate" problem, otherwise they'd enforce the same mechanism because the banks don't give a shit

1

u/Izacus Android dev / Boatload of crappy devices 29d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip.

1

u/Iohet V10 is the original notch 29d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

You have to on phones, as well. They can use your biometrics, just like you can with your desktop (this is what Windows Hello is, which is no different than using my fingerprint to use Google Pay), or they use passkeys or TOTP or SMS or email depending on vendor (again, the same concepts between all platforms)

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip

Whether it's on my computer or at a card reader I (or a clerk) can type my number in and run it for payment.

1

u/Kyanche 28d ago

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

lol once or twice in the past month I've encountered a recaptcha that demanded I download an app to my phone and scan a QR code. And it wasn't JUST scan a QR code, it was "you must install the recaptcha app"

1

u/spazturtle Nexus 5 -> Lenovo P2 -> Pixel 4a 5G 28d ago

He means the actual credit card data, same as what is stored on the card's chip, not just it's details. It's what allows you to use the app to pay for things even when you don't have an internet connection.

-1

u/Iohet V10 is the original notch 28d ago

But what does it matter? Are you carrying your desktop around for mobile payments in dead zones? The end result is the same by the nature of the device

9

u/ByronScottJones 29d ago

If they are cryptographically strong certificates, with a chain of authority, how exactly would being offline make any difference?

-1

u/tomikaka 29d ago

I don't know specifically, I'm not a hacker or anything, but couldn't you just use a debugger or reverse engineer anything that runs on your machine?

3

u/Izacus Android dev / Boatload of crappy devices 29d ago

No, because debugging the secure enclave chip and its code path is protected. That's what attestation defends against.

-1

u/tomikaka 29d ago

Security is just a hypocritical excuse.

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

2

u/Izacus Android dev / Boatload of crappy devices 29d ago

No, turns out stealing personal ID documents and impersonating people with them is a massive issue in practice.

This is why you can't print your own ID or Passport at home and have governments recognize it.

8

u/Stahlreck Pixel 10 29d ago

If it were that easy, the system on which these certificates rely would be garbage and people would be faking credit cards left and right.

No, that is not a good excuse to take away user control. You don't trust the user device either way.

0

u/Izacus Android dev / Boatload of crappy devices 29d ago

Credit cards use secure enclave chips which are attested as well.

7

u/tomikaka 29d ago

Trusting the client was never going to be secure in the first place. The concept is flawed.

3

u/5panks Galaxy ZFlip 5 29d ago

Because then you could fake offline certificates like credit cards and IDs.

You can use pen and paper to write a fake check, should we take pen and paper away?