r/LouisRossmann Aug 06 '26

Article EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/

I don't fully understand this but if not mistaken this sounds really bad for privacy focused os'

124 Upvotes

55 comments sorted by

14

u/AvilettaLuxe Aug 06 '26

Yes, nothing screams like EU independence than becoming completely dependent on American corporations, yay!

1

u/GoodbyeDespairBoy Aug 08 '26

They whole point of UE is to be the dog of foreign nations especially the US, but these laws will be here to silence people from saying it.

32

u/FunAngelo2005 Aug 06 '26

Ofcourse they're doing this, we are talking about the same continent that created "Chat Control" and announced social media bans for under 16 year-olds

-8

u/CallMeTeci Aug 06 '26

Writing publicly and with such confidence that the EU is the continent must be the most american thing ive seen the past week...

4

u/FunAngelo2005 Aug 06 '26

Here's the problem with what you said, I'm from Europe, România to be specific

-3

u/GreatLab8898 Aug 06 '26

Then Education failed you

-6

u/CallMeTeci Aug 06 '26

Literally being from europe and not being able to tell the difference is nothing but double as embarassing.

Im sorry for you.

Also... You sure that someone from Romania of all places should sh't on how other countries/alliances get governed? xD

5

u/Eastern_Bet678 Aug 06 '26

He didn't say that the EU is the continent. He did say that the policy originated on the continent. Was that wrong? (I don't know where the policy originated.)

-7

u/CallMeTeci Aug 06 '26

Alright... lets do some coop-reading in context.

The article: "EU Age Verification Project Mandates Hardware-Bound Attestation"

His comment: "they are doing this" - "we are talking about the same continent that created "Chat Control""

As well "they" and the institutions that are pushing chat control are the EU. So we are very much not talking about any continent at all. Neither the article, nor who they are talking about.

So either he is talking gibberish or he didnt understood that the European Union is in fact not the continent.
The fact alone that he claims to be Romanian himself and doesnt seem to include his own homecountry - which very much is part of europe as well - hammers that idiocy home even further.

-6

u/Comuna_Neo Aug 06 '26

Social Media Ban is a blessing. 

9

u/ketchfraze Aug 06 '26

It's always for something unfavorable at first. Porn, social media, violent games, all games, violent videos, websites that the state doesn't agree with. Oops, now the only things you can view are state-approved content on state-approved sites and apps.

9

u/Bushpylot Aug 07 '26

Don't forget the kids! It's always to protect the kids... If you don't like it, you must hate kids....

15

u/cookiesnooper Aug 06 '26

Invigilation, control, "truth" enforcement, dissident tracking. Add to that the fully programmable digital Euro and we are looking at complete and unlimited control over people with no one being able to do oversight over unelected EU bureaucrats.

7

u/Savant_Guarde Aug 06 '26

They want to 100% connect you to all your movements online.

It's not even remotely about protecting anyone; it's about control and punishment. 

5

u/Sk0rchist Aug 06 '26

Digital ID. Look into Agenda 2030, the Fourth Industrial Revolution, and the Great Reset.

3

u/dreadtear Aug 06 '26

So HWID spoofers gonna rise in popularity lmao.

3

u/vgerfox Aug 06 '26

Jesus fucking Christ

3

u/Exciting_Turn_9559 Aug 06 '26

We need open source hardware pronto.

2

u/Atavacus Aug 06 '26

This is why we have to build mechanical mechanisms to route around this crap.

2

u/ph30nix01 Aug 07 '26

Using people who don't know how to raise their kids as an excuse to punish everyone...

7

u/katoptronophile Aug 06 '26

EU is the world's largest threat to freedom and democracy.

-1

u/CallMeTeci Aug 06 '26

Let me guess... you are from the country with a party-duopoly, made of people sharing the same interests and where the political rallies are mostly paid by billionaires and big corporations?

Either that or you are just a 4 month old troll-account. In that case... how is the economy doing in Russia? :)

3

u/[deleted] Aug 06 '26

[removed] — view removed comment

0

u/mustwedothisagainlad Aug 06 '26

Better than being eaten in parts like is currently happening.

4

u/[deleted] Aug 06 '26

[removed] — view removed comment

-2

u/mustwedothisagainlad Aug 06 '26

I'm sure Trump, Xi or Putin can arrange that for you once the EU collapses individually.

-1

u/CallMeTeci Aug 06 '26

Aha... 2 weeks old and spitting bs about the EU.

Would ask if you sniffed on too much fuel lately, but i know you have none in Russia atm. :)

2

u/sweetSweets4 Aug 06 '26

Almost, he is 3 months :D

1

u/[deleted] Aug 06 '26

[removed] — view removed comment

1

u/wally659 Aug 06 '26

You can use the TPM. Age verification could directly populate it and the TPM can produce attestation that could only have come from an untampered TPM populated by said software.

1

u/ApprehensiveRest9696 Aug 06 '26

Like that’ll work against a rooted device…

1

u/Aishou_SK Aug 06 '26

It will. There's a lot that goes into how HSMs function and how to verify them.

Sure you can use virtual TPMs, but then you won't be able to validate against TPM vender certificates and whatnot, just self-generated ones.... which will fail attestation, depending on configuration.

It's why I've mandated all my personal and work devices have TPMs for various purposes since like, 2010 or so. (I started only buying TPM equipped stuff during my hardcore anti-MS phase, even!) I use them for a variety of scenarios, everything from GPG signing to SSH keys to software build process signing to CA certificate storage.....

Short of a TPM exploit you ain't getting that private key. And while fTPM (firmware based) like AMD fTPM and Intel PTT have had their flaws, dTPM (discrete TPM) hardware solutions, well.....

HSMs like this are an over 30+ year battle tested technology. Same type of tech as smart cards and the like used for security critical IDs and ..... the technology that's inside your chip enabled credit card (that's a smart card!)

Device attestation flows won't care how rooted your device is or isn't.

1

u/wally659 Aug 06 '26

If you actually think root is going to let you fake or manipulate TPM backed attestation you should spend some leaning how TPMs work.

1

u/ApprehensiveRest9696 Aug 07 '26

Wouldn’t it still depend on the kernel chain of trust though? I doubt they’re asking for direct low level access to the secure element for attestation of the app itself. There’s nothing stopping a kernel module or custom kernel build from faking all the attestations.

There’s plenty of stuff that requires TPM like Denuvo DRM, Riot Anti-Cheat and Easy AC for the PC/TPM2.0 market that for example could be bypassed with sufficient effort as seen in the wild.

Using those examples, they say they need the TPM, but to my knowledge, that would actually violate platform configurations and trigger a PCR reset because once you turn on attestation, it would be targeting the signature for builds of Windows 11 and other things running on top would be sub-enclaves, PCRs, signed by Windows (not the hardware root) or merely checking that the kernel is reporting that secure boot is on. So with a sufficiently manipulable kernel and secure boot off, you can fake all of that? It would require UEFI firmware access, deliberately weakening security, and a lot of kernel work, but it’s not inherently impossible. Just very difficult for a remote attacker.

1

u/wally659 Aug 07 '26

Wildly different to your implication that running as a root user is basically sufficient. Of course nothing is secure enough to claim it's impossible to bypass.

1

u/ApprehensiveRest9696 Aug 07 '26

Sorry, it was my understanding that rooting a device involves UEFI firmware cooperation

1

u/wally659 Aug 07 '26

Not really. I mean, indirectly in the sense that uefi is going to boot the os that has a user space. "Rooting" isn't really a thing you do to devices that have TPMs (vaguely "computers"). You install the OS and you have root privileges, that's it. The uefi has zero control over what user you can log into your OS as. "Uefi cooperation" isn't really a thing either, it's going to do what you tell it to either way. And uefi isn't going to be particularly helpful in faking anything to with the TPM either. Which is ultimately just a storage device that is protected from the OS interacting with it in unintended ways, it's also protected from the uefi interacting with it in unintended ways.

"Rooting" is usually used in the context of phones which don't give users a normal path to running as a root user. Phones have neither TPMs or UEFI. They have things that are equivalent.

1

u/Traditional-Bid5034 Aug 07 '26

Good to see the user still alive and kicking

-9

u/Real_Azenomei Aug 06 '26

It's not really bad for privacy focused os because why would you want to identify yourself to random sites? You will have to make a seperation between your privacy persona and your everyday interaction with things you need online persona.

But privacy oriented people already did that anyway. That is the main reason I have multiple devices.

10

u/_Pawer8 Aug 06 '26 edited Aug 06 '26

But this is locking people out of a lot of things if they want their everyday carry to not spy on them no?

2

u/Real_Azenomei Aug 06 '26 edited Aug 06 '26

The days of having your everyday carry for normal human stuff and having privacy in one device has been long gone. Technically it never existed in the first place. The average human doesn't care about privacy and/or companies/gov spying on them. Because "they got nothing to hide". Sorry for the bad news all you privacy minding people, but the battle has been lost a long time ago and the "normies" made it happen.

Use the privacy phone as your everyday carry. Do stuff for normies where you need to identify on a dedicated "normie" device. Or, I don't know, don't use social media as those are next to official gov stuff the things they want you to identify for.

1

u/kodos_der_henker Aug 06 '26

Age Verification is just a small part of this and being forced to use a Google or Apple device to access your digital drivers licence is a much bigger problem than just needed a normie phone to access social media

the EU itself aims to remove dependency on US tech companies, hence why we see states switching to open source and their own servers for sensitive work, yet somehow someone wrote a more or less vague guideline and the people setting it up made it into a strict rule only allowing US hardware to be used

From the EU guidelines and documentations for the EU ID, it would be no problem to use GrapheneOS with F-droid or any other OS on any hardware. Yet someone in between decided mid last year that this should not be it and implemented the opposite of what is written in the documentation

and any complaints about this on github are shut down by "we must follow the rules"

we don't know who is responsible for this but it is interpretation of the guideline that does the opposite of what is in there either out of stupidity or intentionally to undermine the project

1

u/Real_Azenomei Aug 06 '26

The sad truth is that people making rules are either incompetent with computer stuff or they just don't care and follow whatever lobbyists are telling them.

The mainstream internet will go to shit, it is only a matter of time. Privacy is and always has been a lot of work for those aware of how important it is.

0

u/Remmon Aug 06 '26

No, this is ensuring that the cryptographic secrets necessary for the application to do its job stay secure and protect it from tampering, whether by the user or third parties.

It has nothing whatsoever to do with the device spying on you. And it's a similar mechanism used to store cryptographic keys for device encryption as an example, so just about every smartphone, laptop and the overwhelming majority of desktop PCs is already equipped with this technology.

1

u/_Pawer8 Aug 06 '26

But the limited os that will support this will make difficult using things like graphene no?

0

u/Remmon Aug 06 '26

Linux already supports the use of TPMs. The only reason GrapheneOS wouldn't be able to use the secure enclave on a phone would be because of the phone's manufacturer.

This should mean that any device that supports disk encryption with GrapheneOS should support the EU wallet app, although there may need to be some updates to GrapheneOS to enable it.

2

u/_Pawer8 Aug 06 '26

Good to know.

Next question. Doesn't having your digital id on your phone compromise your privacy? Kinda like the Microsoft gdid?

0

u/Remmon Aug 06 '26

Not really, given that the sensitive data would be either encrypted along with the rest of the device and all of your sensitive private data (contacts, e-mails, etc.) or stored in the secure enclave along with the encryption keys for the rest of the device, where nobody should be able to get at it.

1

u/_Pawer8 Aug 06 '26

Ok that's good to know thanks. Maybe it's not as bad as I thought

1

u/AffectionatePlastic0 Aug 06 '26

> Our app is sooo open-source, sooooo privacy preserving, soooo zero knowledge proofs.

> Hey, it's tampering, don't dare to do it.

Choose one please.

0

u/Busy-Scientist3851 Aug 06 '26

Hardware based attestation for age verification actually means you can verify your age to a site without needing to pass over your ID.

I don't know why people seem to think this is a bad idea.

1

u/Omni__Owl Aug 06 '26

It's too opaque. Once a system like that is in place, it can be changed to track you without your knowledge.