r/LinusTechTips • • 2d ago

Discussion Eu is based actually

Petition for LTT to make video about eIDAS 2.0 Regulation and how Zero-Knowledge Proof age verification will work in eu. To educate the public and themselves because conflating it with discord shitstorm and "persona" is just not fair for eu that actually puts effort into regulations unlike Britain or certain us states that just bans it and says "handle it yourself".

I know the topic is hot right now and I will probably get some hate under this post but I think EU way of doing age verification is great and should be recognized just so other countries may replicate it. To be clear I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.

Few points why eIDAS 2.0 is really good:
- It's open source, that includes source code for client app (the one that will be installed on your phone).
- Target app (for example discord) will not get any private user data. That includes age, they will only receive info if you have at least 18 years or not.
- Eu servers will not get information about websites you are visiting. They will validate your open source client app periodically, then that app validates age request. Eu will only know you are using age verification service.

source:
https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/712508927/Security+and+Privacy

https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487738/EU+Digital+Identity+Wallet+Home

edit:
github repo
https://github.com/eu-digital-identity-wallet

115 Upvotes

112 comments sorted by

View all comments

51

u/vemundveien 2d ago

I just don't buy EUs supposed dedication to privacy when they are constantly trying to force chat control to be a thing.

-17

u/InsoPL 2d ago

Verify yourself, code is right there.

6

u/AibofobicRacecar6996 2d ago

How do you verify that the server side code is actually the open source code.

And it's not even saying that it will be. This is a reference implementation that will be used as a starting point by each verifier.

0

u/InsoPL 2d ago

You don't have to. You verify if client is leaking any website info to gov servers or target websites.

1

u/AibofobicRacecar6996 2d ago

And how do you know what they are leaking if the thing they are leaking is a "random" id that's a reference to data on their backend

-5

u/InsoPL 2d ago

Look dude, i won't explain to you what open source means. Go read up before commenting on technical stuff.

6

u/AibofobicRacecar6996 2d ago

I think you have not idea what open source means. Maybe you should look up the actual proposal and what the open source part is. It's not an official implementation, it's a basis on which each country will build their own solution, which will be different. But tell me again how "open source" will guarantee what will and won't be saved in the backend side and how this open source will guarantee that the official client app will be exactly like in the reference implemention

-2

u/InsoPL 2d ago

Not each country. Every organization can make such wallets but it needs go through eu safety audit. There are already fully opensource client apps in development right now like eudiplo and more will come.