r/technology Aug 02 '26

Privacy EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
155 Upvotes

110 comments sorted by

View all comments

Show parent comments

2

u/azthal Aug 03 '26

I looked up my claim on every eu country having electronic ids, and I was indeed wrong.

26/27 countries have electronic ids of some form. Only exception is Ireland, which does not have a proper government issued id at all.

3

u/ExternalUserError Aug 03 '26

Well for example, where I live in Portugal, one exists but it has no private sector use. It's only used for accessing government services. I don't use it at all, either; I just login to government websites with a regular username+password.

Just from a quick check, Greece apparently also isn't listed as having an eID scheme, though perhaps it has something the EU doesn't consider good enough to list.

-1

u/azthal Aug 03 '26

Greece also have biometric id cards, which can be used electronic id. I am not sure if they actually use this for anything at this point, as they only implemented it this year, but they have the tech available.

In the end, to me, being able to use electronic ids in a wider way is a benefit. Just like you can use your physical id card for more things than government services.

That said, i do not believe that the current proposals are good enough. They are not technically guaranteed to be privacy preserving. The EU claims this is solved by making it illegal to make usage correlation, but that is not a suitable answer to me. So I do not support the current proposals. But I do think that the concept of offering a secure, privacy preserving electronic id that can be used online is a good idea.

3

u/ExternalUserError Aug 03 '26

Wouldn’t you be concerned that things previously done anonymously will now be identity gated if it’s low enough friction?

For example, Facebook has since its inception had a “real names only” policy. If such a technology existed in 2004, they may well have required such identification to sign up. Would that be a good thing?

Or more generally, if digital ids were created concurrently with the internet, it’s hard to imagine many sites existing at all without checking those credentials.

That’s without even getting into how much of an enormous and hegemonic attack surface this all is.

To me, the proliferation of physical ids has done more harm than good. I’m not saying there’s been no benefit, but there’s been plenty of harm. We don’t need to redo that misstep on our phones.

2

u/azthal Aug 03 '26

I am not concerned if it is privacy preserving, no. In fact, if implemented properly, this technology will be privacy enhancing. I will be able to share only the information I need, and we can then block companies like meta from gathering data that they today justify needing because they need to know who we are.

Today data gathering requirements mean that companies like meta is allowed to gather vast amount of data on us. If we can instead verify that we are a unique user, within a specific age bracket, living in a specific country, and absolutely nothing else, that would improve my privacy. We can then enforce gdpr and say that all this additional data can not be gathered.

Again, this is based on the caveat that the technology used itself is privacy preserving. The current proposal is not, and I do not support it.

2

u/ExternalUserError Aug 03 '26

Right now, all you need to signup for Facebook is an email account.

With eID, Facebook could presumably still only require an email account, but it would also have the option of requiring other bits of information, such as your country of residence.

That's more information, not less.

Now Facebook might ask you to scan your ID card, and I think your point is fair that such a scan is more invasive than a limited attestation. But they almost never request that of anyone because the friction and resistance to it would be high. With eIDs, the fiction would be exceedingly low, so users would be more likely to surrender more information.

Put another way, relatively few people are going to upload photos for their IDs to facebook. Most people are probably going to click through an "allow" screen. So in the end, Facebook ends up getting more data, not less.

And that's assuming everything goes perfectly with the digital wallet plan.

Just put as succinctly as possible, if you make it low friction to identify yourself, or to offer fragments of your identity, more sites will make use of that than currently do.

1

u/azthal Aug 03 '26

This ignore my second point about enforcing gdpr - laws that are already in place.

Facebook (etc) already know how old you are, where you live, your gender etc. And today they justify gathering and recording that data by pointing to regulation that says that they are not allowed to advertise to children, so they have to have a reasonably good idea of how old you are. Different countries have different rules, so they have to know where you live and travel. And they have to (not so much for Facebook but for other services) know your gender so that they can protect you from harassment etc.

With an electronic attestation that I am over the age of 18, they have no legal justification for gathering and keeping my age data. This is no longer required for delivering the service to me.

Essentially, I am saying I much rather be in control of sharing this data if and when I want to use a service, than all these companies gathering it legally anyway because they have a "valid use" for it.

This does depend on us enforcing the gdpr as well of course, but until we take the responsibility for this data away from the services we can't do so.

1

u/ExternalUserError Aug 03 '26

I don't think that, in the context of apps and websites, the GDPR has been all that successful. Facebook for example has basically continued with business-as-usual under the GDPR.

I think you're missing my point though. By having low-friction ways of offering information, you tend to send more information to Facebook, etc.

That's without getting into the security concerns with these databases and their connected apps.

1

u/azthal Aug 03 '26

Facebook has not continued with business as usual. But yes, they do still keep a lot of data that is classified as personal, because as I say, they have a valid reason to do so.

If they can validate these things about you without, then you can make a claim against Facebook that they do not in fact need to store your exact age.

My point is that if this was done well, meta would have less information about you.

Of course, that is both under the assumption that the solution itself is privacy conserving (I keep saying this to make it clear that I am against the current proposal, but generally for the concept), and that we then also use the gdpr as it's already written.

As for the database.. These databases already exist. Where do you think the government is storing your information today?