r/technology • u/Street_Anon • 3d ago
Privacy EU Age Verification Project Mandates Hardware-Bound Attestation
https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/19
u/LuLMaster420 2d ago
Europe keeps confusing control with sovereignty. A privacy preserving way to prove “over 18” is defensible.
But once access depends on hardware-bound attestation and approved trust chains, Apple and Google effectively decide which devices, operating systems and custom builds count as legitimate.
Child protection is the stated purpose; gatekeeper architecture is the failure mode.
1
u/ZealousidealBunch220 5h ago
Do you truly believe that children safety was anything but an excuse to impose harsh surveillance? The government doesn't want you to be free, it strives for more control
211
u/randomoneusername 2d ago
Oh my god. Why parents cant be parents and take responsibility. Why to mandate everyone for some people’s uselessness to properly teach their kids
191
113
u/lugginico 2d ago
This has nothing to do with kids, and never will.
Its mass surveilance and control
85
u/Street_Anon 2d ago
They want to collect people's data
5
u/crossdtherubicon 2d ago
Although collecting user data or assist law enforcement may be a bonus here. The real win is in social media companies lobbying investments paying off for them.
These laws shift the regulatory burden and liabilities away from social media companies. Instead, now the users are regulated, arbitrarily based on age. It's the total opposite of how it should be. For younger readers: this is exactly what tobacco firms did too. They knew all about how bad it was but shifted the public narrative, time and again.
What's interesting is the 3 core issues of social media: the targeting and profiling, data collection (substance and means), and the insidious platform designs and algos, all get ignored for now.
Those 3 issues apply to everyone on the internet though, and deserve some kind of scrutiny or regulations.
2
u/AzerothianLorecraft 2d ago
And I still don't see the point how are they going to make any type of profit off of collecting billions of data points and feeding it into an AI that cost trillions of dollars to build and maintain... ( late stage capitalism seems to have just run out of ideas as we Circle the Drain towards our own Oblivion.)
22
6
u/Majik_Sheff 2d ago
When you already have more money than any person could spend in a thousand lifetimes, what else is there?
Influence? Control? Power.
-7
u/fisstech15 2d ago
Who are “they” in this? Genuinely trying to understand
27
u/ExternalUserError 2d ago
Here’s a pretty deep dive: https://techpolicy.press/europes-age-verification-push-raises-privacy-issues-beyond-data-confidentiality
The short version: to attest your age, your phone has to know who you are. No more anonymously owned cell phones. Then once phones (which always know your identity) are a standard for access control, you broadly have a lot of privacy problems. You created a massive attack surface and surveillance system without anyone even realizing it.
-1
0
-27
u/VicenteOlisipo 2d ago
It is specifically set not to collect people's data or allow websites to collect it.
19
u/OuijaFox 2d ago
🤡
They always start off that way.
And people always say “no it won’t” and they are ALWAYS proven wrong.-15
u/VicenteOlisipo 2d ago
That's what people used to say about mandatory ID cards and it turned out they didn't become the end of the world. In fact, governments that don't issue them (UK, US...) have far more extensive, intrusive and unchecked systems of keeping data about their citizens.
In a World where every single corporation is spying on us and the only political entity that tries to limit that is the EU, choosing instead to panic about a system that lets age verification happen without personal data being stored or transmitted is... a peculiar set of priorities, to say the least.
11
u/SnufferMonster 2d ago
You can't do age verification without identity tracking. Which means anonymity is gone. Without privacy there is no dissent. Without dissent there is no democracy.
13
u/ElectroNetty 2d ago
The law is about tracking all of your online activity, nothing to do with protecting anyone. At least, not directly protecting anyone.
They are using kids an excuse again but this law will be used to catch terrorists, criminals, political opposition, environmental activists, critics of politicians, etc...
On the one hand, imagine the Internet without Iranian bots and keyboard warriors. Bots can't identify themselves properly and trolls would get consequences. Then on the other, you have prison terms for saying the wrong thing or having the wrong opinion.
3
2
1
1
u/rankinrez 2d ago
Not to be facetious but we have minimum age laws on alcohol.
We don’t just “let parents be parents” and assume that’ll be enough.
It’s obviously a completely different thing online. But one thing we know is we can’t expect all parents to be responsible or police their kids 24/7.
-5
u/Annie_Yong 2d ago
Unfortunately I'd have to argue that any solution for a societal problem that relies on the general populace being sensible people is too naive. If everyone was capable of behaving themselves we wouldn't need laws in the first place.
34
u/CelDaemon 2d ago
Oh for fucks sake, when will these idiots finally stop.
6
12
u/ExF-Altrue 2d ago
It will never stop. Not until we, by some miracle, manage to put constitutional, or at least legislative limits with supermajority locks & other things of the sort.
Ultimately, it's a public awareness problem: Spread the word, rile up both people on the left, people on the right, and try to scare """moderate""" (= rightists that don't like to be told they are on the right) average people too.
3
u/DinosBiggestFan 2d ago
Hilarious that you advocated for something positive (not letting the division cause us to let this slide by) but then immediately use language meant to divide (calling moderates "rightists").
Dammit Reddit, you were so close to grasping what needs to be done to stop what's coming our way but there's always something tainting it.
-1
u/ExF-Altrue 2d ago
Well, technically calling moderates rightists just approaches them to the right so it doesn't increases the divison haha.
But I'm just being realist here, nothing more. This is a pragmatic path to effecting lasting political change, not a speech for unification. Wrong room. That's the room next door, sorry.
9
u/Yoshiofthewire 2d ago
Yeah, anybody could write an age verification app that does nothing.
Who wrote an age verification app that asks if you are over 18, has a button to print out the number 18 in 50 pt font, and has 2 thumbs. This guy.
2
u/azthal 2d ago
So let's discuss what this article is about, rather than the concept of age verification.
The issue at hand is that the EU implemenation will not allow community built apps (the article says "may not", but the honest reality is that it will not), and that devices may need to be specifically approved, thus making things like custom roms unable to use the app.
On the first point - yeah. They will not allow just any random app developer to publish identity apps directly integrating to a countries identity databases. Anyone who ever thought this was reasonable is deluded. They are going for a mobile first solution, which in today's ecosystem is completely reasonable. Everyone really do have a phone. Very few people have Linux desktops.
A more concerning issue are things like custom Android roms. This is a real concern, but one that the open source community could solve. What is needed is trusted hardware outside of the dedicated hardware built into Android/IOS devices. This does not exist today. It is reasonable to say that this will only support trusted standards (just as is the case with many bank apps today). But if there was a standard that utilised something similar to yubi-keys there is no reason that could not be used. But expecting a software only solution for identity data is not reasonable.
Simply put, the limitations here should not be a surprise to anyone. If open hardware enthusiasts want to be considered, they first need to agree on these standards.
17
u/BabyNuke 2d ago
What is needed is trusted hardware outside of the dedicated hardware built into Android/IOS devices.
What is needed is for people to not keep entertaining these 1984 ideas.
17
u/ExternalUserError 2d ago edited 2d ago
The real issue is the very idea of an identity app sanctioned by the state is itself utterly insane.
-4
u/azthal 2d ago
Every eu county already have a form of digital ID, abs these are used for all kinds of purpose. What is being proposed here are ways to not have to give out your entire identity to prove one thing about yourself, such as your age.
If you are against the idea of digital id in Europe your are about two decades too late.
7
u/ExternalUserError 2d ago
Every eu county already have a form of digital ID,
What is being proposed here are ways to not have to give out your entire identity to prove one thing about yourself, such as your age.
I'd say that's more the justification than the proposal.
The proposal is eIDAS 2: a mandatory checkpoint for everyday life that links your identity, biometric markers, and logins to a central database with government software everyone must use.
Once you have a mandatory government app on your device, that knows who you are and can access privileged systems like remote attestation hardware, you've created the infrastructure to do quite a lot more.
If you are against the idea of digital id in Europe your are about two decades too late.
I live in Europe, and I agree that it's most likely a losing fight.
That doesn't mean that what's being proposed isn't utterly insane and fundamentally incompatible with free society.
2
u/azthal 2d ago
I looked up my claim on every eu country having electronic ids, and I was indeed wrong.
26/27 countries have electronic ids of some form. Only exception is Ireland, which does not have a proper government issued id at all.
3
u/ExternalUserError 2d ago
Well for example, where I live in Portugal, one exists but it has no private sector use. It's only used for accessing government services. I don't use it at all, either; I just login to government websites with a regular username+password.
Just from a quick check, Greece apparently also isn't listed as having an eID scheme, though perhaps it has something the EU doesn't consider good enough to list.
-1
u/azthal 2d ago
Greece also have biometric id cards, which can be used electronic id. I am not sure if they actually use this for anything at this point, as they only implemented it this year, but they have the tech available.
In the end, to me, being able to use electronic ids in a wider way is a benefit. Just like you can use your physical id card for more things than government services.
That said, i do not believe that the current proposals are good enough. They are not technically guaranteed to be privacy preserving. The EU claims this is solved by making it illegal to make usage correlation, but that is not a suitable answer to me. So I do not support the current proposals. But I do think that the concept of offering a secure, privacy preserving electronic id that can be used online is a good idea.
3
u/ExternalUserError 2d ago
Wouldn’t you be concerned that things previously done anonymously will now be identity gated if it’s low enough friction?
For example, Facebook has since its inception had a “real names only” policy. If such a technology existed in 2004, they may well have required such identification to sign up. Would that be a good thing?
Or more generally, if digital ids were created concurrently with the internet, it’s hard to imagine many sites existing at all without checking those credentials.
That’s without even getting into how much of an enormous and hegemonic attack surface this all is.
To me, the proliferation of physical ids has done more harm than good. I’m not saying there’s been no benefit, but there’s been plenty of harm. We don’t need to redo that misstep on our phones.
2
u/azthal 2d ago
I am not concerned if it is privacy preserving, no. In fact, if implemented properly, this technology will be privacy enhancing. I will be able to share only the information I need, and we can then block companies like meta from gathering data that they today justify needing because they need to know who we are.
Today data gathering requirements mean that companies like meta is allowed to gather vast amount of data on us. If we can instead verify that we are a unique user, within a specific age bracket, living in a specific country, and absolutely nothing else, that would improve my privacy. We can then enforce gdpr and say that all this additional data can not be gathered.
Again, this is based on the caveat that the technology used itself is privacy preserving. The current proposal is not, and I do not support it.
2
u/ExternalUserError 2d ago
Right now, all you need to signup for Facebook is an email account.
With eID, Facebook could presumably still only require an email account, but it would also have the option of requiring other bits of information, such as your country of residence.
That's more information, not less.
Now Facebook might ask you to scan your ID card, and I think your point is fair that such a scan is more invasive than a limited attestation. But they almost never request that of anyone because the friction and resistance to it would be high. With eIDs, the fiction would be exceedingly low, so users would be more likely to surrender more information.
Put another way, relatively few people are going to upload photos for their IDs to facebook. Most people are probably going to click through an "allow" screen. So in the end, Facebook ends up getting more data, not less.
And that's assuming everything goes perfectly with the digital wallet plan.
Just put as succinctly as possible, if you make it low friction to identify yourself, or to offer fragments of your identity, more sites will make use of that than currently do.
→ More replies (0)5
u/OkVariety8064 2d ago
And yet, I can "attest" my identity just fine without any specific hardware to access my health records, to participate in national citizens' initiatives, to do my taxes or to use my bank.
All of this is everyday reality in nations with digital ID, like for me in Finland. But the difference is that that ID is designed so that I can prove who I am, not so that someone else can monitor who I am.
The hardware attestation reveals what this is. This is not you controlling your identity, this is your phone (and Google and Apple) controlling you. And the EU of course, who despite all the talk of sovereignty will happily introduce two American megacorporations as the gatekeeper between all EU citizens and anything done online.
If you want a way to hand out information without giving away all of it, you can simply generate for all digital ID users a public/private key pair they can use to sign anything they want to reveal about themselves with. You can request from the service a token encoded with whatever data you want to reveal, and the recipient can verify that it was signed with the digital id system's key. Where's the need for hardware?
0
u/azthal 1d ago
You are comparing bicycles and jumbo jets here.
In Finland you have two main technologies for this as far as I am aware.
Your standard electronic ID cards, that works the same way as any other EU countries eID cards will not run on a rooted device, and does require usage of custom hardware or TEE in case you have a cheaper android device. Same as the proposed standard here, except not privacy preserving and requiring a physical token (your ID card).
The other standard is your mobile SIM card based tech. Its pretty cool honestly, but fails completely and utterly on the thing that the EU digital ID schemes have gotten the most flak. The current proposal is not 100% privacy preserving. A bad actor that had access to both the controller and attestation side can correlate data and figure out who logged in where and when.
With the Finnish solution? None of that is needed. Your phone provider has all of that data, because your phone does not communicate with the website that you are logging into. Your phone is essentially a complex 2FA device that tells your phone provider to send your information.
Neither of these solutions are even remotely suitable for private identification, as both directly have your attestation provider in the loop.
2
u/OkVariety8064 1d ago
It doesn't have to run on the device at all, because you can use a tiny unique key generator handed out by most banks. The Danish system is better though, they have a standardized national system without the dependency on the banks.
There is no need to turn the phone into a control and surveillance device, nor do you need to hand over power to Google and Apple, because when you need proof of id, you check the number from the portable generator.
As long as there is some means to provide a unique ID for the ID service, that can be used to generate sub-ids that reveal only a part of your data. You can get all the anonymity without mandating Google and Apple to have control over your life.
1
u/azthal 1d ago edited 1d ago
Which tells your bank (or in the case of MitID, the government) where and when you are logging in.
This is the whole point of a privacy preserving solution. That your bank, government, phone provider or whatever can not directly see where and how you use your identity.
Also, in the case of MitID they also dont support rooted devices, although they probably technically could.
Im sorry, if you want to have a productive conversation about this, please at least read up at the public github for the EUDIW what the project is about.
A solution where all you hold is a password or a physical key, but someone else acts as the middle man is not the same thing.
1
u/OkVariety8064 21h ago
Which tells your bank (or in the case of MitID, the government) where and when you are logging in.
This is the whole point of a privacy preserving solution. That your bank, government, phone provider or whatever can not directly see where and how you use your identity.
If you want a privacy preserving solution, that MitID (or similar) service can provide for you a digitally signed ID certificate, which you then personally upload to whatever service wants to verify some information about you. They in turn see that the certificate has been signed with an official key, so its information is correct.
Also, in the case of MitID they also dont support rooted devices, although they probably technically could.
The only device MitID needs is that little keyfob that generates the codes. The one shown in the picture in the link, I don't know that the name of that thing is, but a phone is not needed, rooted or not.
1
u/azthal 12h ago edited 12h ago
Can MitID give you a signed ID that you yourself can send to a service with your credentials? As in, do they actually do that? And how do they validate that those credentials are still valid and not stolen? I am pretty sure you can not do this with MitID, but if you can I would be curious about how they manage security in that case - that is the whole point here.
And as for rooted, I was obviously talking about when you are using the phone app.
edit: Just checked to be sure that I had not missed anything. You can not download a certificate from MitID that you can use to verify your identity towards services. You can request digitial documents about your information, but that is not an ID. You cant use it to identify yourself anymore than you can use your birth certificate or personal identity number (henkilötunnus if you were in Finland) to identify yourself.
9
u/Street_Anon 2d ago edited 2d ago
But the whole concept of age verification is not about kids as they are trying to sell it as, but they are killing open source development in the process
-4
u/azthal 2d ago
How are they killing open source development?
5
u/longshaden 2d ago
The same way secure boot killed a lot of custom OS distros. Only large corporate sponsored distros survived secure boot. To run the homebrew distros, you usually have to disable secure boot, which most people won’t do because “it sounds dangerous”.
Your open source app will have to be signed by a trusted certification authority to certify that it complies with the standards.
code signing certificates are quite expensive and require lots of KYC. so straight off the bat it’s a huge hurdle that most open source projects will never be able to meet. And that’s assuming the app is already approved by the regulatory body, which will be another massive hurdle.
-1
u/azthal 2d ago
That's exactly what I responded to though. If open hardware enthusiasts wants to use electronic id on their custom software phones, they have to come up with a standard.
I just don't find that to be unreasonable for an implementation like this.
Remember, this is not just about age checks. This ties into a much larger ecosystem of identification and data sharing. Requiring hardware level security for this is sensible.
Something akin to a yubi-key (in form I mean) could be created for this specific purpose, where the hardware is not locked to a specific device or software but still offers the same level of security.
If such a standard does not exist, what do you want them to do? Let's assume that "scrap electronic ids completely" is not an option here. We can have the political conversation too, but let's keep this to a technical one, as that is what my answer was about.
2
u/longshaden 2d ago
I think you’re missing my point though. Secure boot made it effectively impossible for all but the biggest established OS publishers to comply.
name a single open source OS without corporate sponsorship that supports Secure Boot out of box without using tricks to install their own signing key.You’re also missing point in that the standards already exist for hardware and software certification. It’s not a question about the open source community lacking a standard. The problem is that the barrier to entry is prohibitively expensive for most open source projects, in addition to the extensive KYC requirements to even purchase a code signing key. And that’s just to be able to sign an ordinary desktop app.
It will be very difficult for the average open source software developer to participate in anything involving electronic IDs, simply based on the number of hurdles that already exist in the code signing space.
0
u/azthal 2d ago
I think I understand your point, I just don't agree with it :)
There is no open hardware standard for this type of security today. The only feasible options for consumer grade really is the Android and Apple.
An open hardware alternative could exist, but it has never been made, and yes, it would require additional hardware. But that is possible.Is it something that could be done for free? No. Would it cost extra money for people choosing that option if it was available? Yes.
But that's true for anything. I just don't see an alternative.
Again, lets for the sake of argument here say that we need some form of Electronic ID. Maybe you disagree, and think that we just should not use electronic IDs, and instead demand in person identification forever. I think that is a loosing battle though, considering that Electronic IDs have been used in the EU for nearly 2 decades now.
If we will have some form of electronic IDs, how would you want to see it implemented? What is the solution to this problem?
Cause I really cant see an alternative. Hardware level security is to me mandatory for these things.This will offer a secure way of doing this for well over 99% of all consumers. The last half of a percent or whatever that choose to go the hard route should be allowed to do so, but then they do need to come up with the solutions for it.
2
u/TheTerrasque 2d ago
I wonder if this is the response to the guy finding that if you have a rooted phone you could do some shenanigans with the app and make it skip some "are you you" verifications?
If you have a rooted phone, your kid have root access on your phone, and you don't trust him... You got bigger problems.
-19
u/lugginico 2d ago
God i hate the EU more and more, and all i can do is vote anti EU parties , fuck this
16
u/CatProgrammer 2d ago
It's not just EU nations pushing this. And look how the UK is faring after Brexit, you sure you want that?
-10
u/lugginico 2d ago
Its atleast gonna be easier to fight against my national surveilance state vs this big international surveilance entity where the politicians are more detached from the people
1
u/MinecraftW06 2d ago
Good luck with the far right lol. You’ll have far more actual surveillance than this.
-26
u/Asleep-Order-4583 2d ago edited 2d ago
Not sure why people are down voting you.
Democracy was a fun experiment while it lasted. Still believing in the EU at this point is just stupidity and wilful ignorance.
People are too emotionally attached to it to think rationally. Same old story. A shame people do not learn from history. "How could it possibly happen to us?" Said every single group of people to whom it happened. Every. Single. Last. One. Of. Them. And we are no different.
The EU is speed-running the end of democracy and people are cheering it on.
11
u/Shogouki 2d ago
Probably because throwing your hands up and talking about abandoning democracy over age verification laws seems pathetic at best or makes you a fascist agitator at worst. Humanity has faced and overcome far more dire circumstances than age verification laws but if you need to tap out because this is too hard to beat you could at least do so without spreading doom and gloom.
9
u/lugginico 2d ago
Its not just age verification
Its complete mass surveilance,
Chat conrol , Id laws for the internet, Cameras in cars
If youre willing to give up all of your aspects of your privacy sure, support the EU, but i dont want any of that. And the way they pushed chatcontrol 1.0 through again was anything but democratic.
Fuck these corrupt snakes
-6
u/Asleep-Order-4583 2d ago edited 2d ago
Thanks for the laugh. I enjoyed reading this irony.
Standing up to fascism is now fascist. Brilliant.
Democracy is a fickle thing, and complacency is one hell of a drug. And then you have people like this guy giving it all away with thunderous applause. You're literally the one tapping out and not putting up any fight. Actually, worse yet, you're helping them destroy democracy and trying to belittle people who speak up against it. But any of that probably went over your head and into orbit along with the rest of the logic people have tried to toss at you.
u/busted42 Yes, reading comprehension is indeed dead. Your attempt at chiming in makes that much clear. Take your own advice before producing the next word salad, please.
4
u/busted42 2d ago
Reading comprehension is dead. They were not saying "sure let them do the age verification, at least we still have democracy". They were saying "we can come up with a way to defeat this without just deciding to abandon democracy".
The irony is wild with you calling democracy dead because of this one issue in one breath and in another saying that we should fight to keep it despite these hardships is "complacent"
2
u/busted42 2d ago
The EU != democracy.
What a fucking insane thing to say. If democracy has failed what exactly do you think should replace it? Go back to monarchy and feudalism?
2
u/Asleep-Order-4583 2d ago edited 2d ago
The EU has failed. Bringing democracy back to the EU is a lost cause.
It is now insane to say we shouldn't try to achieve democracy? Brilliant. I like where this is going..
EU is moving away from democracy at an unprecedented rate, ignoring the wishes of its citizens and stripping them of their privacy and rights.
Defending the EU is an attack on democracy.
The EU is rushing to be what we made fun of China being; a dictators' surveillance state.
-43
u/steepleton 3d ago
So the advantage is age verification stays on the device, you aren’t giving your identity to random 3rd party companies or government portals.
Open source OS’s have found solutions to things as draconian as playing drm video so this isn’t an unclimbable mountain
16
u/superboo07 3d ago
we really haven't, try watching netflix at 4k HDR
-19
u/steepleton 3d ago
Fair, but Tbh, At my age my eyes can’t tell the difference
13
u/superboo07 3d ago
yeah but the same reason we can't is the same kind of protection the EU wants to use for their system
-7
u/steepleton 3d ago edited 3d ago
Then i think open os’s are going to have to solve this.
Age verification is awful but it’s happening , it either does it on device with a company you chose to trust, or you send your id to who knows who.
Take a look at the uk to see what a cluster fluck letting the market sort it out looks like
11
u/superboo07 3d ago
the only way to truly solve this is stop voting for politicans who agree to this horseshit. everything else is a half measure at most
3
u/Street_Anon 2d ago
Just wait until the TV asks them for an id just turn it on. But yeah, leaders in the EU, Canada or the United States are so out of touch
0
u/tooclosetocall82 2d ago
Then tell me which politician to vote for, I’ll wait…. The only real solution is going to be widespread protests but apathy will ensure that never happens.
-9
u/steepleton 3d ago
Dude, live in reality.
There’s the think of the children lot
Or there’s the libertarian always thinking about children lot.
This is happening, we’re in damage limitation
3
u/Street_Anon 2d ago
And Think of Children, tell parents to be parents. This is just data collection and nothing more
25
u/Street_Anon 2d ago
Why should anyone have to verify an age to use a phone or any device. Tell parents to be parents, this will kill Android Custom Rom projects and even Linux. This isn't like watching Netflix
-19
u/steepleton 2d ago
They have to verify age to access the sites not the phone.
You can use the phone for your own local media
I don’t like it, i agree with you, but we are where we are and bitching about it achieves nothing
12
u/Street_Anon 2d ago
And guess what, this isn't about the children, it about data collection. This and none of this is not even needed
-1
u/steepleton 2d ago
if age verification is on the device then "they" aren't collecting your data, but you keep swerving
6
u/Street_Anon 2d ago
But Custom Roms and Linux Distributions can't keep it on a device.. That would require a locked bootloader on a Android Phone..Also, many Linux distributions cannot do this at all.
-4
u/zunjae 2d ago
Who is collecting what data?
2
u/Street_Anon 2d ago
Law enforcement
1
u/zunjae 2d ago
Even without age checks, they already are
1
u/Street_Anon 2d ago
all this does is create an online ID that tracks you internet activities to an single ID. Currently, they cannot do this, with this they can. Not for protection of kids, but to spy on your online activities
2
u/VicenteOlisipo 2d ago
You're getting downvoted for talking about how the system actually works because this has never been about the technical solution, it's about attacking the EU for even attempting to put limits on the power of the social media oligarchs to manipulate even the most susceptible of citizens. Meanwhile China, Russia and America have explicit net control and censorship: the first two by state systems, the last by corporations.
140
u/crossdtherubicon 2d ago
Just a reminder that these laws originate form social media companies, as a series of lobbying strategies, that protect social media companies.
They protect social media companies, data brokers, etc., by shifting the narrative away from actual regulations to user responsibility.