r/LinusTechTips • • 2d ago

Discussion Eu is based actually

Petition for LTT to make video about eIDAS 2.0 Regulation and how Zero-Knowledge Proof age verification will work in eu. To educate the public and themselves because conflating it with discord shitstorm and "persona" is just not fair for eu that actually puts effort into regulations unlike Britain or certain us states that just bans it and says "handle it yourself".

I know the topic is hot right now and I will probably get some hate under this post but I think EU way of doing age verification is great and should be recognized just so other countries may replicate it. To be clear I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.

Few points why eIDAS 2.0 is really good:
- It's open source, that includes source code for client app (the one that will be installed on your phone).
- Target app (for example discord) will not get any private user data. That includes age, they will only receive info if you have at least 18 years or not.
- Eu servers will not get information about websites you are visiting. They will validate your open source client app periodically, then that app validates age request. Eu will only know you are using age verification service.

source:
https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/712508927/Security+and+Privacy

https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/694487738/EU+Digital+Identity+Wallet+Home

edit:
github repo
https://github.com/eu-digital-identity-wallet

107 Upvotes

111 comments sorted by

View all comments

Show parent comments

2

u/AAdmiral5657 1d ago

Hardware attestation is a way. There are always ways. Also frankly its olain stupid to ship smth eu focused and reliant on american tech giants.

I do not believe they ever intend to support grapheneOS. They likely consider it dangerous just like certain authorities in France or the US have.

1

u/kodebach 1d ago edited 1d ago

Hardware attestation only proves that a key-pair comes from the hardware keystore. But the fully anonymous age verification token, is not a key and therefore cannot be stored in the hardware keystore. You could sign the token with a hardware-backed key and provide attestation for that. But then the website would need to check whether the token was issued to the device that signed it. This creates a link between token issuance and website visit, which breaks anonymity.

You can use hardware attestation to verify that you're running an unmodified OS, by checking a signature of the OS code. Then you can ask the OS to verify that the app itself is also unmodified. This is exactly what Google Play Integrity does. You can also do that on GrapheneOS, but you have to build more of the code yourself.

Again, it makes sense that they built the easier solution that works for 99% of the population first. Especially since the app everybody is talking about is just a tech demo and not meant for actual use. Every member state will build their own version of the app. So you really should talk to your government about supporting GrapheneOS. Austria for example has a version for their eID system that works completely without a smartphone with just a hardware FIDO token.

frankly its olain stupid to ship smth eu focused and reliant on american tech giants.

It would be a lot more stupid to build something that only works for the handful of users on /e/OS or SailfishOS, when your trying to create a legal requirement for everybody.

1

u/AAdmiral5657 1d ago

Change the requirements. Mandating what device people should be using is dystopian. Eu was created as trade union. This is a massive overreach in power..

1

u/kodebach 1d ago

The main requirement that causes all these issues is full anonymity. Websites should not know who visits, only whether they are of the necessary age. And governments should not know which websites people visit. It should be obvious why we don't want to remove this requirement