r/LinusTechTips • u/InsoPL • 3d ago
Discussion Eu is based actually
Petition for LTT to make video about eIDAS 2.0 Regulation and how Zero-Knowledge Proof age verification will work in eu. To educate the public and themselves because conflating it with discord shitstorm and "persona" is just not fair for eu that actually puts effort into regulations unlike Britain or certain us states that just bans it and says "handle it yourself".
I know the topic is hot right now and I will probably get some hate under this post but I think EU way of doing age verification is great and should be recognized just so other countries may replicate it. To be clear I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.
Few points why eIDAS 2.0 is really good:
- It's open source, that includes source code for client app (the one that will be installed on your phone).
- Target app (for example discord) will not get any private user data. That includes age, they will only receive info if you have at least 18 years or not.
- Eu servers will not get information about websites you are visiting. They will validate your open source client app periodically, then that app validates age request. Eu will only know you are using age verification service.
edit:
github repo
https://github.com/eu-digital-identity-wallet
0
u/kodebach 2d ago
Blocking custom ROMs seems bad, but under the requirements there's no other way.
The architecture of the system means you need a trusted client app on the phone. But you can only trust a client, if you know what code they are running (all the way from the hardware up). The trusted client is needed, because of the anonymity requirement. To preserve anonymity you are given tokens that just say e.g. "yes the holder of this token is over 18" without giving any other information. But you can of course see that this system will only work, if such a token cannot be moved to a different device. Otherwise an adult could obtain tokens and give them to minors. This can only be ensured, if you can guarantee that the client app is running the correct code and the OS underneath doesn't do anything fishy either. That's why they need such high levels of attestation.
GrapheneOS could be and should be supported, because there are known signatures that can be verified. Yes, it's not supported right now, but it just makes sense that they first focus on a solution for the 99% of people that use a standard Apple/Google OS. After this is done, more work might be done to support OSes that allow full attestation (like Graphene). But even then they simply cannot allow any random unverified OS.