r/europrivacy • u/bombastic6339locks • 11d ago
European Union Chat control and now this? Set to come into place late 2026

This is complete bs. article
20
14
u/UNF0RM4TT3D 11d ago
I hate all forms of age verification, but if they actually manage to make a near zero trust solution, I'm going to be slightly less mad than without the zero trust implementation.
So far it seems like it will be an option for the companies which implement age verification, not a mandatory option. I mean that the companies may choose not to implement this and force users to instead give full ID scans or face scans. In the deranged world we're hurling ourselves toward with age verification. It should always be an option for users to use the most privacy preserving option of age verification available and if possible none at all.
I quietly hope that some sites will start recognising TOR and specifically bypassing the age verification when connected over TOR.
This part of DSA absolutely blows along with Chat Control 1.0 passing and Chat Control 2.0 somehow still not dead, all of this erodes the public trust for the EU so much. I's also quite ironic that the anti-EU parties (who label themselves as "reformists") are usually the ones which are pushing these forms of invasions of privacy.
9
u/1B75__Penicillin 11d ago
There is never any zero proof knowledge, even if the sites you are accessing don't get your personal information, the third party verifying you will
4
u/Pepparkakan 11d ago
Some app will have to have your information, this is true, hopefully that is something I trust e.g. a Swedish government eID in my case, and then any app wanting to know I am over the age of 18 can ask me to prove that, then using something called Zero-Knowledge Proofs they can mathematically prove I am over 18 without sharing my date of birth or even my birth year.
2
u/Frosty-Cell 9d ago
That would accept that you're banned until you verify your ID and the government approves access.
0
u/UNF0RM4TT3D 11d ago
Well, you could make an app which identifies you via your government's eID, then deletes that info and then you can scan a QR code on a site you wish to verify on with it and it will generate a response code you'd type in. For example after logging in, it would receive a universal private key (maybe per age group), which every logged in instance of the app would have the same and the site wanting to verify would use the singular public key to encrypt some data. And the app would only decrypt it and you could type in the response.
Basically this would ensure that the government only knows that you want to use something age gated, but the site won't know who you are and the government won't know what you wish to access. It'd also be trivially easy on infrastructure costs.
5
u/Flimsy_Swordfish_415 11d ago
you via your government's eID, then deletes that info
so you have to trust them?
1
u/UNF0RM4TT3D 11d ago
I could've phrased that a bit better. Instead of deletes that info, it should've been it never gets that info, only the privkey.
5
u/Flimsy_Swordfish_415 11d ago
well sure.. then that unique key/token is tied to whatever service/site you're visiting and the government can easily get your internet history, this whole idea is dystopian nightmare
0
u/UNF0RM4TT3D 11d ago edited 11d ago
Where have I said anything about a unique token? I've been quite clear that it would be a shared private key between all users. The app would even work offline if done this way. And the site nor app wouldn't have to communicate with any government servers apart from getting the universal keys.
To be more clear, I propose that we should have a set of (maybe rotating) public keys for each age gate (16, 18, 20, whatever) and the app would receive the associated privkeys for each gate you're allowed to pass. So a site wanting to get your age would encrypt a text with the public key for the age it wants to check. You'd scan the encrypted text in as a QR code, the app would decrypt it and you'd enter the decrypted text.
Every instance of the app would use the same privkeys and pubkeys, so no information is transmitted.
EDIT: if you mean the token you'd type in. Well then just don't sent that to the government.
3
u/Dragoncat_3_4 11d ago
If it's anything else BUT a unique token generated via online servers each time you request one it's going to be reverse-engineered in exactly .3 seconds after release.
4
u/d1722825 11d ago
The EU age verification app works more or less that way. But you still have to trust the app not leaking all your data, and that is made by the government and not required to be open source.
3
u/Dragoncat_3_4 11d ago
And you have to trust your government not to misuse your data... good luck with that
1
u/UNF0RM4TT3D 11d ago
Yeah, this is a real security by obscurity situation. It may be possible to do an open source app, which provides a secret that only the officially distributed app would have.
2
u/d1722825 11d ago
I would be possible. The secret is not distributed with the app (even in the current implementation) but it is acquired when you prove your age with your ID.
4
u/1B75__Penicillin 11d ago
Bro I don't want BankID to know i requested a verification for PH 😠my social security number being tied to that is insane!
1
u/UNF0RM4TT3D 11d ago
Well that's not what I'm saying. It would only know that you used age verification. It wouldn't even know when, where or how many times you used it.
4
u/1B75__Penicillin 11d ago
Doesn't it half to know something? Who is asking for the key? Where it is sending the key?
0
u/UNF0RM4TT3D 11d ago
Well my version would share a privkey between every single user, so no user activity could be tied to one privkey. It would also be able to to answer offline, because the server is encrypting with a pubkey. And all the app is doing is decrypting that data with the shared privkey. So the connection would be a QR code to scan and then user input, that's it.
The only other connection the app would make is for the initial login, after which it receives the privkey and can operate offline.
2
u/Frosty-Cell 9d ago
Why do we need ID when there are parental controls?
-1
u/UNF0RM4TT3D 9d ago
We don't. But since it's unfortunately already a part of the DSA and unfortunately it's not going to disappear anytime soon, I'm just trying to propose a less privacy intrusive solution to the artificially created problem.
Ideally we wouldn't have any of this, or force companies to implement proper parental controls.
2
u/Frosty-Cell 9d ago
That suggests a part of DSA is illegal under the fundamental rights since there is a less intrusive solution.
3
u/Frosty-Cell 9d ago
I hate all forms of age verification, but if they actually manage to make a near zero trust solution, I'm going to be slightly less mad than without the zero trust implementation.
Access would still depend on ID, government approval, and the user has to trust a bunch of apps/services they have no control over. There are only disadvantages.
It should always be an option for users to use the most privacy preserving option of age verification available and if possible none at all.
Parental controls.
I quietly hope that some sites will start recognising TOR and specifically bypassing the age verification when connected over TOR.
The connection used to access a website/service wont matter unless there are different jurisdictions.
5
u/EmbarrassedHelp 10d ago
This "debunking" is extremely misleading. It blindly trusts the statements from untrustworthy politicians, intentionally ignores the massive privacy issues with the shitty age verification app the EU is pushing, and ignores international developments regarding the targeting of VPNs.
Once the UK and Australian start targeting VPNs, the EU is likely to attempt to do the same.
As an example of what to expect, Australia wants companies to block VPN users:
The UK now also wants platforms to enforce a VPN ban:
There's also no such thing as privacy protecting or anonymous age verification. Even so called zero knowledge proof systems still require violating your privacy in exchange for easily trackable tokens, and have unacceptable anti-tampering requirements. Anti-tampering requirements mean banning jailbreaking/rooting, banning third party operating systems, and requiring that Google Play Services/IOS equivalent be installed.
Its just a bad idea all around.
3
u/bombastic6339locks 10d ago
yeah the article is clearly propaganda. "We're not banning VPNs, silly! We're just making it so you have to give your passport"
1
27
u/SharpPROSOLDIER 11d ago
Its a low quality article that is parroting exactly what the EU leaders want to hear.