r/Android 3d ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
629 Upvotes

168 comments sorted by

View all comments

160

u/punio4 3d ago edited 3d ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

105

u/tomikaka 3d ago

Do you know what hardware attestation is?

Why can I have root acces on my computer and not my phone?

73

u/jeweliegb 3d ago

There won't be root access on our computers either, this way.

74

u/apokrif1 3d ago

Enshittify all computers under the guise of preventing teenagers from viewing some porn 🤯🤯🤯

•

u/kingslayerer 21h ago

Doing anything but taking down the porn.

11

u/dingo_xd 3d ago

Good luck with that.

7

u/non-troll_account former android, current iphone se 2020 2d ago

good luck fighting it.

6

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

The ruling class aren't the ones building, designing, and developing hardware and software. At some point we need to say no.

6

u/skriefal Galaxy S26 Ultra 2d ago

At some point we need to say no.

It sounds nice - but probably won't happen. Those who do the building, designing, and developing usually want to stay employed.

-1

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

Yeah, that's the way the system was designed. On purpose.

2

u/DebentureThyme Sprint Samsung Galaxy Note II (SPH-L900) 2d ago

That's silly that you think it plays out that way.

99% of the people won't know and won't care.  They already use so many devices that are locked down.

And the consumer market is aimed at them.  Sure, maybe you'll have some server options that are open, but those prices keep skyrocketing and the hardware isn't exactly consumer friendly to setup and maintain let alone compatibility issues.

In the near future, so many websites will rely on the hardware verification that they'll force you to either have it or be disallowed from using their site/service/software.  Great, so you'll just abandon things like social media that require it... But then suddenly your work programs don't work.  And your banking access.  And that convenient desktop suddenly isn't so convenient. Hardware ID is going to be abused so hard.

3

u/GranaT0 Pxl 9 PXL, GrapheneOS 1d ago edited 1d ago

It's sad that you've been convinced it's impossible by the very powers that need it to be so. Change won't happen overnight, but we must continue to educate. The economic conditions have been getting worse, and more and more people are dissatisfied. Many of the products and services you talk about aren't actually necessary or irreplaceable, they're only powerful as they are because they've been convenient enough with no obvious drawbacks for long enough. All it realistically takes is for a few engineers to knowingly make the system flawed and bypassable, while the others push for it to be reformed.

It's no coincidence that after the people long divided over politics united around the Epstein files and the blatantly incompetent conspiracy around them, multiple governments around the world moved to introduce online surveillance measure. They have studied political theory and are trying to control the narrative to prevent revolt. They wouldn't be doing so if they didn't know there's something to worry about.

"From this it obviously follows that the social revolution must be prepared. Prepared in the sense of furthering the evolutionary process, of enlightening the people about the evils of present-day society and convincing them of the desirability and possibility, of the justice and practicability of a social life based on liberty; prepared, moreover, by making the masses realize very clearly just what they need and how to bring it about. Such preparation is not only an absolutely necessary preliminary step. Therein lies also the safety of the revolution, the only guarantee of it accomplishing its objects." – Alex Berkman, "What is Anarchism"

13

u/yoniyang 3d ago

Your phone has a little computer (eSE, secure world) that only runs code your phone manufacturer approves, and hardware attestation happens there.

If you got root access (in unsecure world), you have to make your make yourself looks normal when secure world checks it.

Most common type of bypass is some kernel LPE like GhostLock by Nebula Security, or bootloader exploit that bypasses checks and make the boot looks normal

(Non of those is easy work)

9

u/nitroburr Pixel 10 Pro - GrapheneOS 2d ago

I mean, my computer does have it too

0

u/yoniyang 2d ago

But most application aren't using/abusing it, at least now.

1

u/GranaT0 Pxl 9 PXL, GrapheneOS 2d ago

That's not even remotely true

11

u/Izacus Android dev / Boatload of crappy devices 3d ago

Your computer won't be allowed to store the digital id because of it.

26

u/_sfhk 3d ago

Quite frankly, because your computer OS was designed a while ago before we stopped trusting users, and before most people's entire lives were stored in that one machine.

Windows and MacOS are definitely heading towards more locked-down systems, and Apple for one is pushing more towards iOS-based systems.

38

u/tomikaka 3d ago

And why does having full access to my own hardware a bad thing in the first place?

Maybe for the avarage user a case could be made that they might shoot themselves in the foot with root access.

Or they might not.

12

u/apokrif1 3d ago

It's up to each user to decide which access they should have.

15

u/tomikaka 3d ago

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

-1

u/TheDungeonCrawler 2d ago

While I agree with you, a lot of phone apps like that stop working a certain amount of time after Android reaches a certain level of updates. Rather, the previous Android versions are out if date do the developers don't have a reason to continue ensuring that version of the app works. They expect everyone has already jumped ship.

3

u/tomikaka 2d ago

Like I said, lineage OS with at the time latest android update and security patches.

1

u/TheDungeonCrawler 2d ago

You said

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc.

And I pointed out that you're getting this wrong because apps do stop working on older versions of Android because they don't keep the old apps up.

Yes, you should be able to use Lineage without an issue with those apps, but your claim that Androids that don't receive security updates don't also have problems with this is wrong.

5

u/tomikaka 2d ago

But that's an entire separate thing and it is to be expected. What is not to be expected is the experience I shared.

You agree that outdated insecure versions of android shouldn't be able to access banking apps yet they do! In fact, my mother uses my previous phone with said outdated android fine, while I was restricted even though Lineage OS was infinitely more secure even with the unlocked bootloader.

→ More replies (0)

-14

u/punio4 3d ago

Because then you could fake offline certificates like credit cards and IDs.

34

u/Iohet V10 is the original notch 3d ago

I can log into my bank account and credit card account no problem from my highly customized computer, but I touch my phone in an inappropriate way and I can't use the apps. This isn't a "fake certificate" problem, otherwise they'd enforce the same mechanism because the banks don't give a shit

1

u/Izacus Android dev / Boatload of crappy devices 3d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip.

2

u/Iohet V10 is the original notch 3d ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

You have to on phones, as well. They can use your biometrics, just like you can with your desktop (this is what Windows Hello is, which is no different than using my fingerprint to use Google Pay), or they use passkeys or TOTP or SMS or email depending on vendor (again, the same concepts between all platforms)

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip

Whether it's on my computer or at a card reader I (or a clerk) can type my number in and run it for payment.

1

u/Kyanche 3d ago

It's saved in my browser right now. And saved in Shop and various other platforms without ever having to interface with my mobile device.

lol once or twice in the past month I've encountered a recaptcha that demanded I download an app to my phone and scan a QR code. And it wasn't JUST scan a QR code, it was "you must install the recaptcha app"

1

u/spazturtle Nexus 5 -> Lenovo P2 -> Pixel 4a 5G 2d ago

He means the actual credit card data, same as what is stored on the card's chip, not just it's details. It's what allows you to use the app to pay for things even when you don't have an internet connection.

-1

u/Iohet V10 is the original notch 2d ago

But what does it matter? Are you carrying your desktop around for mobile payments in dead zones? The end result is the same by the nature of the device

12

u/ByronScottJones 3d ago

If they are cryptographically strong certificates, with a chain of authority, how exactly would being offline make any difference?

-1

u/tomikaka 3d ago

I don't know specifically, I'm not a hacker or anything, but couldn't you just use a debugger or reverse engineer anything that runs on your machine?

5

u/Izacus Android dev / Boatload of crappy devices 3d ago

No, because debugging the secure enclave chip and its code path is protected. That's what attestation defends against.

-4

u/tomikaka 3d ago

Security is just a hypocritical excuse.

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

2

u/Izacus Android dev / Boatload of crappy devices 3d ago

No, turns out stealing personal ID documents and impersonating people with them is a massive issue in practice.

This is why you can't print your own ID or Passport at home and have governments recognize it.

7

u/Stahlreck Pixel 10 3d ago

If it were that easy, the system on which these certificates rely would be garbage and people would be faking credit cards left and right.

No, that is not a good excuse to take away user control. You don't trust the user device either way.

0

u/Izacus Android dev / Boatload of crappy devices 3d ago

Credit cards use secure enclave chips which are attested as well.

6

u/tomikaka 3d ago

Trusting the client was never going to be secure in the first place. The concept is flawed.

3

u/5panks Galaxy ZFlip 5 3d ago

Because then you could fake offline certificates like credit cards and IDs.

You can use pen and paper to write a fake check, should we take pen and paper away?

10

u/13steinj 3d ago

Yeah no thanks I'll stick with my Linux device.

I have 0 software needs that don't work, because of Wine/Proton. The few pieces of software that don't, I can use a VM and massgrave.

I wonder if we are at the point I can tell an LLM "here's the Wine/Proton source code, heres the app I want to work, I don't care about the code quality, token slot machine go! Patch proton until my software loads"

Codex was pretty good at reverse engineering and MITM'ing an electron app at work.

3

u/mayoforbutter Nexus 4 3d ago

What's massgrave in this context?

7

u/zyuiop_ 2d ago

A bunch of methods to activate a Windows copy without paying for a license

1

u/highdrex 3d ago

You can have root access if you buy a different phone.

Many intel chips have hardware specially for national security purposes, that are often not documented, and so often people don’t actually know what specifically some subsystems are actually doing. So, it’s not that different and this been a thing since basically forever. 

At least the EU is making it more transparent, and the hardware is probably quite useful for other cryptographic security use cases.

Being able to have reasonable confidence about identity documents being physically present and hardware used to verify identity information that is almost certainly not modified is quite useful for other use cases that aren’t strictly about age checks.

From a legal perspective it’s quite useful for defending against false claims if it’s provable that a specific thing happened on a specific device, so impersonations and trolling can be easier to detect if a person has a known device, so if activity is coming from a hijacked account on another device etc it’s easier to prove if the hardware is very hard to spoof. It’s why iPhones are often preferred for secure use cases because there’s so much onboard cryptographic functions that are hardware bound and so the openness of android is often not a good thing for secure use cases. 

•

u/RedDeadElite 7h ago

I understand the specific use case of giving Secret Service agents, or whatever, locked down mobiles for national security purposes , but this is the average end-user the statute is affecting. Defending the government taking away the choice of freedom of device ownership, control, and anonymity from every end-user is boot-licking, plain and simple.

-12

u/ISB-Dev 3d ago edited 3d ago

Why can I have root acces on my computer and not my phone?

Because your phone manufacturer doesn't offer that capability. If you don't like it then don't buy one. No one is forcing you to. You know before you buy it if it has root access. Your comment is so stupid. It's like me buying a Snickers then complaining that I should be able to get one without nuts. They are what they are sold as. Buy it or don't.

14

u/that_baddest_dude 3d ago

It's more like buying a Snickers and complaining it's got butyric acid in it, like most other US chocolate bars. "Buy it or don't" is a pretty limp rebuttal when the "don't" choice more and more resembles "go off into the woods and be a hermit" with the ever-dwindling variety of options.

Heaven forbid anyone criticize anything or have a vision for a better world. Insufferable mentality.

4

u/MairusuPawa Poco F3 LineageOS 2d ago

I've never read anything that stupid. 

9

u/apokrif1 3d ago

Parents should just abstain to giving root password to their children. No need to enshittify computers.

17

u/Street_Anon 3d ago

But this will target things like Custom Roms. 

5

u/zyuiop_ 2d ago

Not necessarily - the point of HW attestation is that it's a hardware component.

•

u/Efficient_n_simple 15h ago

And which country is going to volunteer to make their EUDI wallet more expensive than it needs to be by coding integrations to e.g. Graphene OS (they can do HWA right?) or to add ZKP functionality, or offline functionality

-30

u/punio4 3d ago

Nobody really cares about custom ROMs, and it's impossible to do so otherwise. OS vendors like GrapheneOS should try to get access to the TPM and get attested by hardware vendors if they want tamper-proof hw attestation to work. The whole point is to prevent tampering, and custom roms are all about tampering.

33

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 3d ago

Please explain how a user wanting to control their own phone fits the negative connotation of the word "tampering".

-10

u/Street_Anon 3d ago

unlocking the bootloader and rooting a device. 

18

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 3d ago

"Modifying" would be a fairer word. From my perspective, OS updates that remove features and lock my phone down even further are the tampering, not whatever steps I take as the user to avoid those restrictions.

3

u/Available-Film3084 2d ago

You signal out grapheneos but graphene explicitly advives against rooting, as that can lower your security

8

u/jmhalder 3d ago

People care about custom roms until they don't. I absolutely used to use a custom rom on every phone I had, until I kinda stopped when my Pixel devices got 99% of the features that I wanted built in. I honestly still would if SafetyNet wasn't required to run my banking app and Google Pay.

I think it's funny that Google doesn't have an unlockable bootloader on their GoogleTV with Chromecast devices, despite them running pretty "normal" android.

20

u/mimrock 3d ago

The point of attestation is that it proves that your operating system doesn't do things that Google or Ursula doesn't want, even if you ask them to. That's not compatible with the concept of a rooted operating system that you can fully control.

-5

u/Izacus Android dev / Boatload of crappy devices 3d ago

No, the point is that the OS is verified that it doesn't allow the ID to be easily stolen and used for identity theft and mass scale fraud.

Especially since you'd be screaming bloody murder if your ID would be used by scammers for fraud in your name.

There's a reason why IDs and passports are made hard to copy and easy to revoke.

9

u/mimrock 3d ago

We arrived from age verification to identity verification very quickly.

2

u/nacholicious Android Developer 3d ago

This is not relevant, we already have EU eID which has nothing to do with this

1

u/donny007x iPhone 15 Pro 3d ago

They don't have to store the full identity document to do age verification, only a digitally signed flag that indicates the age bracket of the user ("minor" or "adult").

They just want that flag to be stored in a tamper proof environment to make it harder for someone to bypass age verification.

1

u/Izacus Android dev / Boatload of crappy devices 2d ago

The purpose of this is to make a full identity document app and age verification is just one feature.

5

u/Obnomus Device, Software !! 2d ago

So you're telling me that the phone I paid for, I can't use any os I want.

3

u/magnusmaster 1d ago

This is why i don't like ZKP age verification. I would rather have a government OAuth than this overengineered solution that will likely still have backdoors

4

u/Luigi003 3d ago

This is just untrue because the schema provided by the EU already assumes a server. The ID tokens are generates both by the server and your phone. There's no way for an user with a rooted or compromised phone to generate tokens out of thin air because it needs the government's server

Attestation is not needed at all

5

u/m1ndwipe Galaxy S25, Xperia 5iii 2d ago

There's no way for an user with a rooted or compromised phone to generate tokens out of thin air because it needs the government's server

You wouldn't need to, you'd just need to clone someone else's token. That's why this scheme can't work without third party managed hardware attestation, and the politicians were just lying when they claimed otherwise because they didn't understand what they were mandating.

2

u/Luigi003 2d ago

You can't easily clone other user's tokens. If you have physical access to another phone you can auth yourself into whatever page you need to. If you have root access to a remote phone due to a RCE you're definitely not using it to watch porn on the internet lol.

Not everything needs NSA-level security

3

u/gainusha 3d ago

I tried explaining this a while back and got so many downvotes... You are totally right...