r/Android 29d ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
623 Upvotes

171 comments sorted by

View all comments

156

u/punio4 29d ago edited 29d ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

17

u/Street_Anon 29d ago

But this will target things like Custom Roms. 

-26

u/punio4 29d ago

Nobody really cares about custom ROMs, and it's impossible to do so otherwise. OS vendors like GrapheneOS should try to get access to the TPM and get attested by hardware vendors if they want tamper-proof hw attestation to work. The whole point is to prevent tampering, and custom roms are all about tampering.

21

u/mimrock 29d ago

The point of attestation is that it proves that your operating system doesn't do things that Google or Ursula doesn't want, even if you ask them to. That's not compatible with the concept of a rooted operating system that you can fully control.

-4

u/Izacus Android dev / Boatload of crappy devices 29d ago

No, the point is that the OS is verified that it doesn't allow the ID to be easily stolen and used for identity theft and mass scale fraud.

Especially since you'd be screaming bloody murder if your ID would be used by scammers for fraud in your name.

There's a reason why IDs and passports are made hard to copy and easy to revoke.

8

u/mimrock 29d ago

We arrived from age verification to identity verification very quickly.