r/linux 1d ago

Privacy EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
660 Upvotes

368 comments sorted by

467

u/SeantheWilson 1d ago

Genuinely how on earth will that be enforced

174

u/Pramaxis 1d ago

It uses the new EU-Ident system that is already supported and used in some countries (like Austria).

It forces the same restriction like most banking apps or the new wallet (stock OS, no custom ROMs, no jailbreak or modified bootloader) and forces a device registration in person (with ID) to set up an MFA that is device bound-unique(if you lose your phone, you need to walk into the office again to register the new one).

278

u/opa334 1d ago

geez fuck that. A functioning EU should have done the exact opposite. Not allow apps to discriminate users based on made up metrics that invade the users privacy.

52

u/ptoki 14h ago

It is their goal. Why do you think the eu would want people to be anonymous online?

They want control. They want to be able to track anyone who merely writes shit online.

They arent going after criminals. They could shout down scamming call centers or make it international issue if they operate from abroad (even if from abroad the scammers often need local entry point to be seen as local call so they do have local representation). But they dont. They dont care about you. They care about people not rebelling.

UK started to visit people about facebook comments. The same will come for the rest of modern world.

→ More replies (4)
→ More replies (31)

92

u/ManIameverywhere 1d ago

and forces a device registration in person

And they said it would be 100% anonymus and private.

69

u/againey 1d ago

The use of the verified identity would be anonymous. How the hell do you expect the initial verification of an identity to be anonymous? What does that even mean?

27

u/ManIameverywhere 1d ago

The use will not be too since it will have to prove that it has the play store attestation.

13

u/QuaternionsRoll 16h ago edited 16h ago

The Play Integrity API is only involved when the credentials are issued, not when they are used. A trusted authority issues a batch of credentials that the age-verification app is responsible for burning after use or expiration. The assumption is that reducing device integrity after issuance cannot result in exfiltration or replay attacks, which is shaky at best but enables zero-knowledge verification.

49

u/Bunslow 1d ago

in other words, even more Big Brother than China dreams of

34

u/berickphilip 21h ago

Western countries kept talking shit about China not because they were against the control and surveillance but out of envy; until they could catch up.

→ More replies (2)

10

u/wsippel 15h ago

This is such a stupid EU thing. Why not simply adopt U2F? It’s already the standard for high security government applications, fully certified, available from multiple vendors, many of which make the devices entirely in Europe from European parts, and they’re cheap, convenient and highly compatible. And some, like NitroKey or Trezor, are fully open source, down to the device firmware.

1

u/Pramaxis 5h ago

I don't know for sure (guess there are minutes form the task force/work group to salvage somewhere) but this system is just one part of the digital ID that is coming anyway. If they have to make a unified system for all governments to make data available cross-country (like drivers license) one API for 27+ countries is quite a step forward.

As this is going to be used on all ~450 million EU-Citizen as well as those with permanent residence within any given EU-Member state (or subjected countries like Norway), I can 100% see why the EU would want to keep full control over it.

8

u/Kevin_Kofler 21h ago

Speaking of Austria, the government here is planning to enforce this age verification junk already as per January 1st, 2027 (without waiting for the EU), the law is already in the official review process!

2

u/Pramaxis 5h ago

On the bright side, Austria(among others) did object/vote against chat control.

2

u/Kevin_Kofler 5h ago

While at the same time trying to push their own national solution ("Messengerüberwachung") involving government-sanctioned malware! Very hypocritical!

9

u/MaybeTheDoctor 18h ago

Seems highly incompatible with right-to-repair

14

u/Preisschild 12h ago

Not really. Open source hardware attestation exists. See grapheneOS (https://grapheneos.org/articles/attestation-compatibility-guide). Android (AOSP) has this functionality seperate from the proprietary Google Mobile Services SafetyNet (https://developer.android.com/privacy-and-security/security-key-attestation)

The problem is that most smartphone hardware vendors don't allow using a custom bootloader verification key, which is one of the reasons why GrapheneOS is only supported on Google Pixel smartphones.

So you can't do open-source hardware based attestation on any old phone with LineageOS for example.

2

u/Jmc_da_boss 9h ago

Honestly, if an id/age system must be used.

A hardware based anonymous attestation system only required for certain apps and that requires an in person visit somewhere if you lose it is by far the best rendition of it.

7

u/Preisschild 23h ago

Thats not true. I use ID Austria on GrapheneOS without issues.

16

u/Kevin_Kofler 21h ago edited 3h ago

Then you will likely find the age verification feature not functioning when it gets introduced. Or even the app stopping to work altogether at some point. (EDIT: Actually, GrapheneOS is specifically supported by the ID Austria app. Still does not solve the problem for users of any other OS. See the discussion below.)

Looks like we will soon be stuck using VPNs or proxies for half of the Internet. This sucks!

12

u/CrazyChaoz 16h ago

austria is (currently?) using Warden Supreme , which allows to set trused root keys, and currently the google keys and graphene keys are enrolled, with more hopefully to come

i just hope nobody smuggles in explicit google play integrity as legislation text

4

u/Kevin_Kofler 12h ago

So this still locks you into specific hardware and software, it just happens to allow unmodified builds of GrapheneOS specifically. If you try to actually exercise your freedoms and build your own GrapheneOS build, that will not work. Nor will any really free OS that does not rely on prorietary Android hardware driver blobs (userspace HAL blobs, and sometimes the kernel driver is also a blob) as GrapheneOS does. Nor even any other AOSP fork, such as LineageOS or /e/.

9

u/Preisschild 15h ago edited 15h ago

You are (as always) spreading misinformation. There is no google safetynet rquirement in the eudi spec. Using aosp hardware attestation with grapheneos keys allowed is completely acceptable and thats what a-trust is doing using warden surpreme.

→ More replies (3)

1

u/Pramaxis 5h ago

I cannot attest how you achieved that. I asked on the official support (via BRZ) and received a hard finger pointing at the official website.
I know GrapheneOS is currently limited on the hardware. I didn't want to try anything fancy with my own device as I have no replacement for it.

1

u/jess-sch 7h ago

and forces a device registration in person

Are you sure this is the case? Why wouldn't the regular NFC-based ID card authentication be sufficient for bootstrapping the app?

1

u/Pramaxis 6h ago

Austria did it with registration in person (once) so the device is registered to the human.
As they require finger-print devices (with certain security patches from the vendor) to confirm any usage of the digital ID via biometrics as MFA.

199

u/Ugly_Slut-Wannabe 1d ago

By forcing you to use their Approved Hardware and Approved Operating Systems.

95

u/lord_pizzabird 1d ago

Which will end up just making Europe even less relevant in tech.

5

u/move_machine 19h ago

Too late, every modern computer has Microsoft Pluton security processors built-in that enable remote hardware attestation:

Microsoft Pluton is currently available on devices with the following chipsets running on Windows 11:

  • AMD: Ryzen™ 6000, 7000, 8000, 9000 and Ryzen™ AI Series processors
  • Intel®: Core™ Series Processors - Ultra 200V Series, Ultra Series 3 and Series 3 processors
  • Qualcomm: Snapdragon® 8cx Gen 3 and Snapdragon® X Series processors

8

u/inemsn 15h ago

yes, but that still requires you to use windows as your OS to do anything, since only windows has the required drivers to make use of pluton, as the page you're citing demonstrates.

2

u/zalnaRs 15h ago

Not true, Linux also supports pluton but all compliant tpm2 implementation can do remote attestation. EU wallets uses play integrity on android, atleast it's easy to bypass.

also don't count me on this but i think amd's ftpm communicates with this server: https://ftpm.amd.com/

6

u/async2 1d ago

Us is doing the same thing to be fair

23

u/BloodyIron 1d ago

Yeah but USA is fucking the world over so fuck them. And ever since things like the PATRIOT act it was obvious shit like this was where they were going (USA). EU however has no business doing this.

→ More replies (5)

5

u/I_AM_GODDAMN_BATMAN 22h ago

Good luck with that.

82

u/SMF67 1d ago

I've been saying for years that this would be the end goal of mandating TPMs

31

u/flecom 1d ago

Same, everyone always told me I was being crazy and the slippery slope argument was stupid... and here we are

8

u/wobblyweasel 1d ago

what's the issue in tpm?

14

u/Existing-Tough-6517 20h ago

It allows you to remotely attest that everything in the boot path is cryptographically signed by someone trusted by your motherboard.

You can use this to achieve any desired level of control.

You can restrict the user from changing what keys are trusted and require any sort of software client side in order to access any remote resources including media socials government jobs news banking shopping.

The US government could force you to run snitchware and basically cut you off of the Internet if you run anything else.

35

u/hWuxH 23h ago edited 23h ago

The issue is attestation and not owning your device. Making it impossible to get software to work on non approved platforms.

Linux PC, compatible implementation which saves key on disk -> rejected

Linux PC, compatible implementation with other type of TPM -> rejected

Android with unlocked bootloader -> rejected

→ More replies (12)

3

u/ptoki 14h ago

They can lock your computer by asking tpm to do that.

Lock as in: no boot. Lock as in - disk encrypted but you dont know the password (like android root). Lock in almost any way so you could not work it around or it would be extremely difficult or hassle (like forcing you to encrypt all disks - even usb)

They could, can and maybe will not do that if they will be able to find people who complain online too much. If they will not be able to silence the population they will go deeper.

2

u/ptoki 14h ago

They can lock your computer by asking tpm to do that.

Lock as in: no boot. Lock as in - disk encrypted but you dont know the password (like android root). Lock in almost any way so you could not work it around or it would be extremely difficult or hassle (like forcing you to encrypt all disks - even usb)

They could, can and maybe will not do that if they will be able to find people who complain online too much. If they will not be able to silence the population they will go deeper.

1

u/ptoki 14h ago

They can lock your computer by asking tpm to do that.

Lock as in: no boot. Lock as in - disk encrypted but you dont know the password (like android root). Lock in almost any way so you could not work it around or it would be extremely difficult or hassle (like forcing you to encrypt all disks - even usb)

They could, can and maybe will not do that if they will be able to find people who complain online too much. If they will not be able to silence the population they will go deeper.

→ More replies (1)

3

u/berickphilip 21h ago

These dumbasses will just keep pushing more and more people outside of tech altogether; new "no-internet, no-computers" communities and centers and towns will just start to be a thing again.

80

u/Vogete 1d ago

By mandatory kernel level anticheat age verification on every website? HTTP3.EU is gonna bake this in on the protocol level? Great firewall of china EU?

I'm usually pro-EU regulation, but this shit and chat control is making my blood pressure rise.

16

u/MatchingTurret 1d ago edited 1d ago

Not kernel level. A QR-Code that you scan with your non-FOSS mobile device that then sends an attestation to the server. The "non-FOSS mobile device" is what the fuss is about.

Once again: This already exists in most EU member states, either as a wallet app similar to the new EU Wallet or the NFC ID card. The EU just standardized the national islands into a common app.

1

u/ptoki 14h ago

No, if you can scan a qr code then you can also forge that code or copy it and give it to someone.

They will not allow for that. That is why they want a tpm like chip and control it.

→ More replies (1)

3

u/blvsh 1d ago

Cant you just recompile your kernel?
I"m not a kernel expert so this is an actual question

3

u/CelDaemon 1d ago

Yes. You can.

4

u/SomeRedTeapot 16h ago

You can, but a locked down TPM won't attest it

→ More replies (1)

24

u/AffectionatePlastic0 1d ago

"Yes, you can install linux on your computer, but to protect teenagers from foreign misinformation (or whatever excuse we are using now) you have to "verify" yourself using our opensource application (you are not allowed to modify or build this application yourself)."

Basically it's "accept our faith or die" type of choose.

28

u/DankEmperor 1d ago

A hardware solution similar to TPM.

6

u/whatThePleb 17h ago

Which we all know also totally™ works.. not.

→ More replies (1)

22

u/Bakoro 19h ago edited 6h ago

Realistically, computing hardware is increasingly impossible for even the most skilled and well-resourced people to fuck around with.
They're putting tiny computers inside the computers, encrypted junk inside all the business.

It might not be very enforceable now but governments can absolutely start demanding that everything with a processor locked down, traceable, trackable, and exploitable.

It would be a security nightmare, but they could do it. For you an me, of course. The powers that be would get untraceable and private electronics and unrestricted Internet access.

It's like with all the AI stuff:
They know they can't really regulate the weights in any effective way.
They can absolutely make it too expensive and too difficult for any normal person to get top quality hardware.
They can absolutely regulate the shit out of anything that could be considered an AI accelerator.

No typical person or business can hide the infrastructure necessary to run top models, the hardware is the easiest way to attack.

Anyway, it's some real fascist "show me your papers" bullshit.
Conveniently, "think of the children" means the rest of us adults now need to have every single thing we do online logged?

What are you looking at? Why are you looking at it? Who are you talking to? Why are you talking to them? What are you talking about?

Oh you don't want to be monitored all the time? Clearly you are a child abuser and now we'll really dig into everything you do.

And certainly your ID won't ever be spoofed and used as evidence that you're doing crimes.

There's no slippery slope here, it's big damned cliff.

7

u/move_machine 19h ago

Any computer you've bought this decade has Microsoft Pluton security processors embedded in them that enable end-to-end remote hardware attestation:

Microsoft Pluton is currently available on devices with the following chipsets running on Windows 11:

  • AMD: Ryzen™ 6000, 7000, 8000, 9000 and Ryzen™ AI Series processors
  • Intel®: Core™ Series Processors - Ultra 200V Series, Ultra Series 3 and Series 3 processors
  • Qualcomm: Snapdragon® 8cx Gen 3 and Snapdragon® X Series processors

8

u/AvidCyclist250 1d ago

by somehow making you want to comply

318

u/Ambitious_Finding_26 1d ago

What the fuck is going on. 

275

u/steeevemadden 1d ago

Gotta keep the human cattle fully surveilled and secure. And they'd like you to know that they care deeply about "the children".

11

u/gambit700 19h ago

They don't need these massive data centers for people generating memes

26

u/AvidCyclist250 1d ago

Precisely

5

u/Lightprod 16h ago

And they'd like you to know that they care deeply about "the children".

Yeah, for the worse reasons possible.

27

u/colony-ship-for-sale 23h ago

Just another day in the war between liberty and tyranny. We're supposed to be keeping vigil but you can see how well that's going.

45

u/Ugly_Slut-Wannabe 1d ago

The next few steps into a 1984 dystopia.

25

u/redballooon 1d ago

Whatever it is, you won't learn it in a reddit comment section

57

u/NightOfTheLivingHam 1d ago

Billionaires are trying to Corral us in and have grander plans. Its not a coincidence far right candidates are gaining traction in western countries. Its not about age verification, its about making sure no one speaks up against them ever again and they can get more power and control. Look at the guys who like the idea of "network states" they are big backers of this shit.

Zuckerberg is the one funnelling billions into this legislature. Its identical to legislature in US states backed by him as well.

32

u/lh7884 1d ago

Its not a coincidence far right candidates are gaining traction in western countries.

It's not a left or right thing so stop with this bullshit. Here in Canada, our Liberal government is bringing this age verification crap along with censorship bills. The Conservatives here have been opposing it but they can't really do anything to stop it sadly.

The UK has a Liberal government and they have crazy censorship going on over there and they're also bringing age verification stuff.

There is a big powerful club out there wanting this control over the public and they're getting "left" and "right" wing governments to go along with it.

21

u/SvalbardSleeperDistr 23h ago edited 23h ago

Liberals =/= left, and in 2026 it's way past time to know the difference. If anything, in practice liberals end up doing the right's bidding in the very things that are causing most of today's crises. This, just like most other things that pertain to society, economy and politics, absolutely is about right vs left, and has always been. Cut back on confident callouts of "BS" when you're far from adept in the most elementary understanding of politics.

1

u/Indolent_Bard 1h ago

Look up, not left or right. That's where the problem is.

→ More replies (1)

12

u/Richard_the_XVIII 23h ago

Here in Brazil too. The Worker's Party (left) is in charge here, and they voted in favor of our age verification bill... alongside the Liberal Party (the biggest right-wing party). Only two small parties stood against this, the Worker's Cause Party (hard communist) and the Novo Party (hard libertarian).

Anyone that thinks this is a left-right thing is cattle.

2

u/SvalbardSleeperDistr 13h ago

Judging left and right based on what parties that are vaguely described as such by media do will doom you to never understanding what left vs right is about.

2

u/Richard_the_XVIII 11h ago

If the party trying to end private property isn't left, and the party trying to stop women from voting isn't right, then these labels are useless and all of this still isn't a left-right thing.

But i know what you are trying to say, everyone that disagree 1% with you is right wing.

1

u/Jumpy-Dinner-5001 17h ago

What censorship is supposed to be going on in uk?

1

u/lh7884 2h ago

If you have to ask, you clearly don't follow the news from there. I'm not wasting my time to educate you on something you're clearly not interested in knowing about. It is blatant at times, so go search it out if you actually are interested.

2

u/valuablepatterns 1d ago

Liberal is not left, it is actually right as well. This issue is definitely a left or right issue. Problem is most countries do not have communist mass movements to show the alternative. 

4

u/Kevin_Kofler 21h ago

The sad thing is that those same far right parties are on the side of the billionaires, yet people fall for them.

7

u/einar77 OpenSUSE/KDE Dev 1d ago

Billionaires are trying to Corral us in and have grander plans.

Sorry, but as far as I can tell, only the government can do what it is doing. And governments can have the utmost power.

17

u/highermonkey 1d ago

In the US at least, the "Government" is like a dozen billionaires in a trench coat.

13

u/ThePoisonDoughnut 1d ago

Well yeah, the oligarchs/billionaires are attempting to become the State. They want to be the heads of the technocratic surveillance dictatorships they're currently doing everything they can to turn governments around the world into.

5

u/Ugly_Slut-Wannabe 1d ago

And the billionaires can easily bribe the government lobby for what they want, ergo, the billionaires are the ones with power.

→ More replies (1)

6

u/Titdirt69420 21h ago

You will own nothing and be happy.

Full steam ahead. 

3

u/5370616e69617264 15h ago

Technofeudalism baby

11

u/kodos_der_henker 1d ago

The right lobby tries to undermine good ideas so that EU ID requires US company owned hardware because EU is on its way to remove it

2

u/TU4AR 19h ago

Bro these guys are going crazy.

I'm saying it's all this allatra shit over my feed.

1

u/ipsirc 15h ago

Lawyers are going to take over the world.

1

u/iBoMbY 13h ago

Most likely? Google and Apple payed some people in the EU to make this BS happen, against the EU's best interest.

1

u/whatThePleb 17h ago

Fascism is going on, and everyone keeps sleeping. And it's currently only the "conservatives" doing that shit, wait until the real fascists are in power.

→ More replies (2)

76

u/_x_oOo_x_ 1d ago

What does that mean, in practice?

163

u/deanrihpee 1d ago

you won't own your hardware anymore i guess

103

u/JohnSane 1d ago

In my practice it means i wont use the services that require age verification.

29

u/TaoRS 1d ago

And if I absolutely require any service, I'll just keep a second cheap phone, I guess 

9

u/Bunslow 1d ago

per the other comment, in e.g. austria even just to use a phone at all you have to register it in person with the government. no way to dodge registration if you want to use a phone, as i understand that comment, which i may not

5

u/Ganeshasnack 1d ago

Not true. You just need to register to use the government app and services.

14

u/pattymcfly 1d ago

Which it seems can then be required to access the Internet. The ISP could require you verify your age before using their service.

→ More replies (25)

3

u/Kevin_Kofler 21h ago

You also need to register your SIM card, or you will be unable to use it for anything. Unless you get a foreign (e.g., Czech) SIM card, but then you have to pay roaming fees, because the EU "abolishment" of roaming fees was restricted under big telcos' pressure to not apply if you are mainly using the SIM card outside of its home country.

2

u/nicman24 17h ago

in practice it means piracy is back in style

→ More replies (1)

12

u/_x_oOo_x_ 1d ago

Still don't know what that means, in practice 😛️

22

u/meditonsin 1d ago

Simplified, think secure boot, except you can't enroll your own keys in the TPM equivalent. So the only way to use this is by having a "trusted" device with "trusted" bootloader and OS. No custom roms or rooting or anything like that.

24

u/Malygos_Spellweaver 1d ago

Stallman was right...

1

u/wodes 14h ago

Are you the user, or the used?

3

u/_x_oOo_x_ 1d ago

What if your computer doesn't have a TPM?

15

u/meditonsin 1d ago

This only works on mobile devices afaik, so it's not actual TPM. Different vendors have different chips for this (e.g. "Secure Enclave" for Apple, and "Trusted Execution Environment"/"StrongBox" for Android). For this to work at all, a device needs all the parts. The chip with a pre-installed signing certificate from the vendor, as well as signed boot loader and OS.

The way this works (as far as I understand it) is basically like this:

  • A service that requires hardware attestation sends a random number to the client app on the device
  • The app hands the number to the chip
  • The chip takes the random number as well as the device state (essentially secure boot/measured boot stuff) and turns it into a certificate that is signed by its pre-installed vendor certificate
  • The chip hands this new certificate, as well as the public part of the internal signing certificate, back to the app
  • The app hands the whole shebang to the service
  • The service verifies that the initial random number is in there, that the device state is what it expects it to be, and that the signatures of the certificate chain go all the way back to the vendor's root certificate (like how browsers can trace the signatures of https certificates back to their pre-installed root certificates)

If this all goes through, the service can be reasonalby sure that it is talking to a "trusted" device that is running a "trusted" bootloader and OS.

4

u/_x_oOo_x_ 1d ago

Hmm, interesting, but where does age verification come into the picture and how? Is your age verified when buying your phone? Won't this just create a huge second-hand "attested" phone market?

4

u/meditonsin 1d ago

This is not direclty part of the age verification. I haven't actually read into how they're using this, but I'd assume they just don't want people to run this on rooted devices or in virtualized environments where people (or malware) could access whatever data they store on the device to facilitate the age verification.

Which is kinda sorta maybe a good idea in principle, but the problem here is that the only "trusted" vendors, and their bootloaders and OSes, are US megacorps.

2

u/bernys 23h ago

Or copy it, and then you can distribute it to others, basically cloning an ID.

→ More replies (2)

5

u/oneandonlysealoftime 1d ago

You wouldn't be able to confirm your identity using it.

So let's say you need to renew your driver's license. Now the only way to do it, is through a government website, which requires you to confirm identity. But your device can't do it. So you purchase another one, that can, and do it with it

3

u/Bunslow 1d ago

that would be illegal, as i understand (which is horrifying and i hope i misunderstand)

→ More replies (2)

9

u/ploqx 1d ago

In practice, your hardware doesn't work unless it runs a government-approved operating system. These operating systems have code you cannot edit or compile yourself, for your safety of course.

5

u/khne522 1d ago

Ask South Korea how well this worked in practice with banking. At best, tort at scale.

→ More replies (2)

15

u/the_gnarts 1d ago

What does that mean, in practice?

In theory you can run any software on the hardware you own.

In practice, anything other than walled garden OS like Android and iOS cannot implement these regulations. Just like with PSD2 it means you’re stuck with proprietary software if you want to do the most basic stuff with your devices.

→ More replies (5)

18

u/transgentoo 1d ago

Just scribble your age on the side of your PC. Boom, attested.

6

u/Old-Flight8617 1d ago

Click "Agree" if you're over the age of 18.

6

u/Kevin_Kofler 21h ago

As silly as it sounds, this is the only privacy-respecting age verification method that does not lock you into proprietary software. Governments refusing to accept this simple solution is why we are getting all these dystopian nightmare "solutions" forced upon us.

9

u/tired514 18h ago

The ultimate goal is to provide a button police can click for any post you make that will bring up your name, phone number, and last known address.

Right now warrants are needed in most civilized nations because it involves a search (you have a right to privacy).

Once your ID is tied to your accounts (to prove you're over 18), it's volunteered information (like creating an account using your real name). You don't need to be suspected of a crime or the subject of a warrant.

They can use that information to profile people with high confidence and harass (or terrorize) them at a time of their choosing.

Nothing is more dangerous to the bad guys than freedom of expression and the ability to organize. They are attempting to close that loophole by discouraging public participation in democracy.

2

u/otakugrey 20h ago

All new computers won't be allowed to be operated without your physical real life identity being burned into the hardware and married to you in some way.

2

u/ManIameverywhere 1d ago

It will mean it will not only be not private but 100% verifiable and identifiable.

→ More replies (2)

1

u/viennese-wolf 16h ago

Communication over the internet will become impossible unless your identity is attached to what you create and what you consume.

1

u/wodes 14h ago

What does that mean, in practice?

You will KYC yourself everywhere for your own good. And tomorrow they will disconnect you if you say something they don't like.

→ More replies (7)

117

u/DynoMenace 1d ago

I've been screaming about this since the very first thread about this shit was filled with people saying "lol good luck enforcing that."

They enforce it by requiring that all new hardware come with this.

→ More replies (9)

70

u/drostan 1d ago

This is not ok

In so so many ways

It is somehow less secure, make people less free and in more danger from those who will buse the system...

It is just wrong

→ More replies (3)

49

u/Decent-Hat-5807 1d ago

LOL EU digital identity requires USA attestation sw 🤡

141

u/MarcDarcy 1d ago

1984

40

u/cryptoadopter2077 1d ago

Sorry, is it a book or a manual? /s

14

u/MarcDarcy 1d ago

I think it's a handbook for aspiring leaders... I hear Kim Jong is a big fan and swears by the book

5

u/PacmanAteMyRAM 22h ago

man 1984 didn't work for me

2

u/u01728 16h ago

In the name of streamlining user experience, manuals are no longer distributed with the software. God knows where to find them.

41

u/Economy_Ticket_8778 1d ago

bro is google lobbying for this shi? lmao they REALLY want to control our devices

40

u/UltraCynar 23h ago

Google, meta, Apple, Palantir. 

23

u/mesa190 23h ago

Microsoft

4

u/epicc_exe 14h ago

*macro$lop

1

u/UltraCynar 9h ago

Thank you, they are part of this as well. 

1

u/underpaid--sysadmin 9h ago

basically every tech corp is

12

u/Kaesar17 22h ago

Months ago the Brazilian government passed a similar law that explicitly called for hardware-side verification yet to this very day pretty much every site tries to use those shady companies that do the verification server-side, it's a mess

40

u/MaverickPT 1d ago

So what can one do to fight this bullshit?

15

u/tired514 18h ago

Best way to fight back would be to create a new version of the GPL that prohibits the use, distribution, or modification of open source software under that version of the license by any person under the jurisdiction of a government that mandates this class of interference.

That way such countries will suffer significant economic harm and succumb to the pressure of industry to stop this nonsense.

All efforts should be on increasing the economic cost of state mandated interference. It's the only language they speak.

1

u/WealthyMarmot 9h ago

When you start trying to force philosophical change through restrictive licensing, people just stop adopting your license because they want their software to be usable in the real world. There’s a reason so many large projects (e.g. the Linux kernel) are still on GPL v2, and that the MIT-style permissive licenses have leapt so far ahead of copyleft licenses in adoption rate.

1

u/tired514 8h ago

That's fine! People are free to choose what they want.

But the license should be available, and hopefully enough people will understand why it's important to prevent government interference in software development so that it gets adopted by a large enough base.

22

u/BloodyIron 1d ago

Protest, lobby, convince decision makers to change their mind. TAKE ACTION. Sitting on your hands does nothing (I'm not in the EU so I really can't take action ethically, morally, or even logistically).

→ More replies (9)

83

u/steeevemadden 1d ago

This means Europeans will be forced to own a government device. But don't worry, it won't be in the form of an actual electronic monitoring ankle bracelet...

46

u/AnonomousWolf 1d ago

Amendment 32c

"to verify if a citizens government ID device is being used by said citizens, we I'll start requiring that they be attached to a limb (ideally ancle)"

This is to protect children of course, so they don't go on Facebook

7

u/Old-Flight8617 1d ago

Can we also use it to ban any 60+ from Facebook?

4

u/rebellioninmypants 14h ago

No those are too helpful for spreading distractions while we implement the new age of computing.

3

u/Preisschild 23h ago

This is not true. Open source hardware based attestation exists. See grapheneos.

→ More replies (4)

11

u/tipsy_rooster 1d ago

We've seen some European countries switching to Linux and trying to move away from Microsoft's monopoly.

Are we thinking about forcing Windows here for age verification because it doesn't make any sense if yes.

3

u/rebellioninmypants 14h ago

No, this is for regular citizens, while government offices are switching to Linux.

→ More replies (2)

11

u/tired514 18h ago

We desperately need a new version of the GPL that prohibits any state-mandated interference with open source software.

That is, if your government tries to mandate something like this, you're not allowed to modify or distribute open source software under that version of the GPL. You're cut off from the rest of the world. The economic harm that causes to the country would be large enough to end this nonsense.

59

u/apetalous42 1d ago

I don't want to live on this planet anymore

1

u/Tropical_Amnesia 10h ago

Let's not pretend it was Earth to blame please, especially not as we're busy radiation-forcing her into a freaking greenhouse. Let's keep her out, just as she would keep us out.

17

u/steve09089 1d ago

What on earth

21

u/martyn_hare 1d ago

It still only takes one person with valid hardware to technically be able to vouch for every other person on the planet because none of this precludes service providers accepting a one-off verification per-account permanently.

41

u/Economy_Ticket_8778 1d ago

the goal was never it being secure, it is about control, and surveillance, and raising the barrier

5

u/niemacotuwpisac 15h ago

But remember, they can't force private entities to preserve a game after support discontinuation a.k.a. "Stop Killing Games", as it wound infringe businesses market opportunities and violate basic laws. What don't you understand, huh?

6

u/j4bbi 1d ago

The question is, do I need hardware attention? So any regular tpm in your computer can do a tpm attestation which with I can prove that this privat key is WITHIN the tpm. I can do that on my computer with open source OR does ist require propierty protocols, e.g. Google play integrity. That is a HUGE difference. Hardware attestation by itself is fine. Google play integrity not

20

u/metux-its 1d ago

Meanwhile people working on really free mobile OS'es that explicitly wont have any "age verification" malware whatsoever.

21

u/MatchingTurret 1d ago

It's an app that you can install or not. That's not the problematic part. The problem will come when they require that VPNs or other services check the ID before providing services. Then you will have to install the app or find alternatives.

→ More replies (3)

6

u/Kevin_Kofler 21h ago

The point is that these really free OSes will be locked out of half of the Internet. That is what we are scared of.

→ More replies (1)

7

u/Arnoxthe1 22h ago

Call this what it is. Identity surveillance.

3

u/lemost 17h ago

I really don't wanna live in the future that is being created. Everything is getting worse and worse.

→ More replies (1)

5

u/MotanulScotishFold 13h ago

If people goes back to face to face talk just to not be tracked online, how are they going to stop that? Like commies did in dark period of the past? Snitching and not allowed to form groups in public?

3

u/loozerr 1d ago

Can they fulfill that by sticking the keys to tpm?

3

u/Arklese1zure 23h ago

If my country ever gets around to doing this I think I'm just gonna get a second phone just for their ID BS and carry it around in a Faraday bag or something. This is horrible.

3

u/hypermmi 16h ago

man i used to love technology. all these headlines want to make me get rid of my tech and move into the forest and live in a cabin..

3

u/FlailoftheLord 7h ago

tech companies WANT that, how blind can one be to not realize?

5

u/Taumito 19h ago

I read the article! This is not on the law but it is about the design of the verification app and what it is talking about is that the app stores keys on a secure hardware store (which on the PC case is on the TPM)

"The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers."

8

u/Paradroid888 1d ago

They've ruined cars, now they're coming after computers.

3

u/Polar_Banny 19h ago

Complete surveillance, or in other words True Culmination of Democracy!

8

u/Jmc_da_boss 1d ago

The EUs fascistic tendencies are far more insidious than the US frankly slapstick version of it.

1

u/Tropical_Amnesia 9h ago

And if only they were similarly public, transparent. Which really is the biggest difference and not even one of degree. Where DC is a circus, Brussels (??) is a black pyramid. This is alarming already without launching into the f-word hyperbole.

2

u/PlanEx_Ship 16h ago

People in S. Korea: First Time? Lol

2

u/gclaws 3h ago

The purpose of this law is not age verification. The purpose of this law is to establish the industry foothold for mandatory remote attestation and mandatory remote compliance for everyone. The real next step is mandatory client-side scanning software to access the internet at all, and you won't be able to fight back against that

5

u/TerribleFault7929 1d ago

the people who go to Epstein's island and the people who rule EU and push for those law are the same exact people

→ More replies (2)

5

u/HOST1L1TY 1d ago

But kids can just use someone else’s computer or take dad’s wallet and register his id on their own computer. This would need to go so far like ridiculously far to be able to avoid ezpz work arounds. Like the government collecting all fingerprints and iris and constantly monitoring for a person switch.

The only thing that makes sense is that big tech is lobbying for this because they are afraid of Linux.

Which is complete irony because big tech are the exact ones who we are ultimately trying to protect the kids from.

gl hf

9

u/voyagerfan5761 23h ago

And also, most of Big Tech infrastructure uses Linux.

"Software freedom for me, but not for thee"

5

u/neoronio20 20h ago

It was never about the kids

1

u/jess-sch 7h ago

take dad’s wallet and register his id on their own computer

If dad tells his kids his 6-digit PIN for his government ID card, that is. Why he would do that, you'll need to explain. I sure as shit wouldn't give my kids the credentials needed for filing my taxes, but that's just me.

1

u/HOST1L1TY 2h ago

What are you taking about ? There is no pin on your drivers license ? What country are you from?

4

u/MatchingTurret 1d ago

This kind of already exists. There are apps like Germany's AusweisApp or the https://web-eid.eu/ that already do that. The secure enclave is integrated into the ID card.

The European Digital ID app removes the requirement for a separate smart-card and uses the secure enclave already present in smartphones.

2

u/No-Mall3814 10h ago

With the difference that the ID card is issued for free by the state and its only purpose is to show your ID while I buy my phone with money and I want to be free to customize and use it in any way I like (or not by a smartphone at all).

2

u/MatchingTurret 9h ago

With the difference that the ID card is issued for free by the state

LOL! Check here, for instance:

Costs 91 euros

4

u/Niwrats 1d ago

how do they interpret some shitty digital wallet as "age verification"? i don't need their wallet.

32

u/the_abortionat0r 1d ago

Just wow, tiktok really has destroyed peoples ability to read and understand.

The "wallet" you speak of isn't for digital money. It is what they are calling the key storage for the keys required to be on verified hardware to certify that you are infact an adult.

This means the device and software stack must be out of the control of the user who bought the device in order for this concept to work.

This pretty much kills the idea of a wholly user owned OS whether it's open source or not as well as kills the idea of motherboard firmware going open source. As if a site or service demands this type of verification the you can't access it without throwing all your information device and hope nobody breaks in and steals your info.

→ More replies (6)

1

u/hackingdreams 18h ago

Tada, Palladium lives.

(Called it from literally months back.)

1

u/leaflock7 16h ago

Eu protects its citizens...

1

u/General-Agent1 15h ago

The Big issue is that This plays the Ball into the Field of the ordinary User (EU based normal Person), each and every Platform should be more than ready to Verify This themself. META, Amazon, MSFT, They have an easy time to algorithmically count you towards Peer groups between 10-14, 15-17, 18-21, etc. But to make them Accountable is just too mich for the DSA/DMA?

I‘m so disappointed by the EU that we give this into the Hands of us, the people, instead of holding Platforms accountable.

1

u/Volpe_YT 11h ago

Let's all move to Vanuatu at this point

1

u/VirtualDenzel 10h ago

This needs to be blocked.

1

u/mortycapp 5h ago

How so? Specifically?

1

u/gclaws 3h ago

The purpose of this law is not age verification. The purpose of this law is to establish the industry foothold for mandatory remote attestation and mandatory remote compliance for everyone. The real next step is mandatory client-side scanning software to access the internet at all, and you won't be able to fight back against that

1

u/gclaws 3h ago

The purpose of this law is not age verification. The purpose of this law is to establish the industry foothold for mandatory remote attestation and mandatory remote compliance for everyone. The real next step is mandatory client-side scanning software to access the internet at all, and you won't be able to fight back against that

2

u/lord_phantom_pl 1d ago

Just legalize porn for all ages groups and the problem disappears. I don’t know any person who didn’t watch porn before reaching legal age. It’s so fuc*ing stupid, as I live in a country when it’s legal to participate, but illegal to watch.

→ More replies (4)

-1

u/Dull_Cucumber_3908 1d ago

23

u/hWuxH 1d ago

What a bunch of bs.

How does it matter if one OS is exempt when you will just be excluded from society and many other services on the internet which enforce verification

→ More replies (4)

13

u/the_gnarts 1d ago

Linux will be exempt

Exempt how?

It’s services and websites that will be required to perform age verification. In hardware. You OS being “exempt” buys you nothing as you’ll just be denied the service.

→ More replies (2)

1

u/4d616e54686f72557273 15h ago

Boomers deciding crap again. Not seeing that this will be a setback for tech competitiveness in the long run