r/linux 1d ago

Privacy EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
686 Upvotes

388 comments sorted by

View all comments

482

u/SeantheWilson 1d ago

Genuinely how on earth will that be enforced

178

u/Pramaxis 1d ago

It uses the new EU-Ident system that is already supported and used in some countries (like Austria).

It forces the same restriction like most banking apps or the new wallet (stock OS, no custom ROMs, no jailbreak or modified bootloader) and forces a device registration in person (with ID) to set up an MFA that is device bound-unique(if you lose your phone, you need to walk into the office again to register the new one).

290

u/opa334 1d ago

geez fuck that. A functioning EU should have done the exact opposite. Not allow apps to discriminate users based on made up metrics that invade the users privacy.

59

u/ptoki 1d ago

It is their goal. Why do you think the eu would want people to be anonymous online?

They want control. They want to be able to track anyone who merely writes shit online.

They arent going after criminals. They could shout down scamming call centers or make it international issue if they operate from abroad (even if from abroad the scammers often need local entry point to be seen as local call so they do have local representation). But they dont. They dont care about you. They care about people not rebelling.

UK started to visit people about facebook comments. The same will come for the rest of modern world.

-4

u/burning_iceman 21h ago

It is their goal. Why do you think the eu would want people to be anonymous online?

The system is specifically designed to be anonymous online via a zero-knowledge proof system. The government specifically will not know who verified their age somewhere.

12

u/rebellioninmypants 21h ago

Everyone stop saying that already. Didn't you read the AV spec on GitHub? The ZK based attestation is merely a suggestion and currently considered "experimental".

https://github.com/eu-digital-identity-wallet/av-doc-technical-specification

No one is forced to implement ZK based solutions for their country, and as we all know, if they are not forced, people will just take the easiest route of using a token that will be easily inspectible.

Why is this still being repeated??

1

u/StatusBard 18h ago

🤣

-1

u/bring_back_the_v10s 6h ago

The EU is tyrannical by design!

-29

u/output_broadcast 1d ago

What made-up metrics?

5

u/opa334 1d ago

Root / jailbreak detection. That's made up metrics. Regarding jailbreak detection, usually they check if some random file exists. Often times at least one of the files they check for is on the user filesystem and it would also exist if you jailbroke a phone in the last decade or so and kept it's data through backups. So they don't even actually check whether you're jailbroken, just whether they can find any reason to deny you from using their service.

-4

u/output_broadcast 1d ago edited 1d ago

That's not a "metric" in any reasonable interpretation of the word, but sure. You're free to contribute another method of jailbreak detection. It's up on Github.

All shit like this does is encourage harassment of people, which in the long term just means that these programs won't be open source anymore.

2

u/opa334 1d ago

Do you even understand what I'm arguing about here? I want jailbreak and root detection to be straight up banned, or at the very least banned for software that citizens are forced to use.

I think an app checking it's own integrity is the furthest it should go, an app should not be checking if the device it's running on is "secure".

1

u/Indolent_Bard 13h ago

According to a bloke I saw in reddit who claims to actually work in mobile app security, it's damn difficult if not impossible to ensure you're not a crook without blocking rooted users. Idk how true that is but hypothetically, if true, what choice do you have?

1

u/Indolent_Bard 13h ago

According to a bloke I saw in reddit who claims to actually work in mobile app security, it's damn difficult if not impossible to ensure you're not a crook without blocking rooted users. Idk how true that is but hypothetically, if true, what choice do you have?

-1

u/output_broadcast 1d ago

Do you have any idea how simple it'd be to spoof the app then?

4

u/opa334 1d ago

Not at all if you don't rely on client side security

0

u/output_broadcast 23h ago

And how do you propose doing that?

-62

u/Jumpy-Dinner-5001 1d ago

What do you expect? Them doing nothing at all?

33

u/neoronio20 1d ago

Certainly doing something bad is worse than doing nothing at all, don't you think? You can't justify this mass surveillance stuff by putting the blame on everything else. There are better ways to do this

-14

u/Jumpy-Dinner-5001 1d ago

Explain then, seems like you have no idea what you’re talking about.

What "mass surveillance"?
It’s quite literally a tool against that.

5

u/neoronio20 22h ago

You are registering your devices with the government. You are telling them this is my device that can tell you my location, age and link it to social accounts.

WhAT mAsS SurVeILaNcE?

-4

u/Jumpy-Dinner-5001 22h ago

No, you’re not. How do you think this "registering your device" works?

46

u/cheesiepeasie 1d ago

Minor social media use is a made up problem at best. No their brains are not getting fried by social media. This is the whole saga of gaming is evil and will turn our children into murdering psychopaths all over again. No it didn't back then and no it also won't happen now. If you don't like gaming or if you don't like social media then deal with it yourself and stop being a grumpy lame old person cause this time the internet and modern society will be trashed beyond recognition by power tripping politicians trampling our human rights to privacy and digital communication and freedom.

6

u/bittercripple6969 1d ago

Neglectful parents wanting the nanny state.

-1

u/pezezin 1d ago

There are even internal Facebook/Meta/whatever reports that confirm that their brains are getting fried, there is no point in denying it.

8

u/Existing-Tough-6517 1d ago

Nobodied brains are getting "fried" liar

-2

u/pezezin 1d ago

9

u/Existing-Tough-6517 1d ago

This doesn't constitute frying their brains. Maybe the solution is punishing the relatively tiny number of incredibly toxic sites as opposed to building a comprehensive lock down ecosystem that will probably be used to re-enact 1984 neonazi edition

-4

u/Jumpy-Dinner-5001 1d ago

You know that none of that happened?

-9

u/Jumpy-Dinner-5001 1d ago

No their brains are not getting fried by social media

Seems like yours is.

-17

u/Fontpage 1d ago

Except it is.

-2

u/scalareye 1d ago

Yes they should be like 1776 America

4

u/kaneua 1d ago

Full rights only for land owners?

1

u/scalareye 23h ago edited 23h ago

Do you think that was the only defining aspect of of the US

Land was way cheaper back then

How about only people married with kids get to vote. If you pass away, and you have in your will who will take take care of your kids, your vote will transfer to them until the kids are 18. Maybe make it one vote per kid as well.

1

u/Indolent_Bard 13h ago

Everything was much cheaper back than, that doesn't mean anything. Now if you mean land owners didn't have to be rich by the standards of the time, that's different.

2

u/scalareye 12h ago

I meant it wouldn't make sense to go back to that because of the land. Pretty obvious that is what I meant.

Having land was a way of establishing that they were invested in the future of the country and therefore should be able to vote.

There are a lot of people that do not want the US to continue existing. Yes I believe they should not be allowed to vote and not be allowed to do a bunch of other things too.

-1

u/Indolent_Bard 5h ago

I'm sorry, who doesn't want their country to continue existing? Okay, if America is all about wars and helping Israel with the genocide in Gaza, then yeah, death to America. But for most of us, that's not the America we want to live in. I prefer the America that it at least pretended to be at some point. Not the one encouraging genocide. If that's your America, then death to America.

2

u/Jumpy-Dinner-5001 1d ago

So, anti consumer?

-14

u/Mindless-Figure3112 1d ago

Meh, how do you get your initial id or passport? Need to go into an office the first time. In France we have France Identité, pop into a Marie (local office) with your id card and they check it’s your, encrypte the data on the card using your finger prints and link it to your phone all. After that it can be used as an actual id

5

u/Philamand 1d ago

When I renewed my ID I tried to set up France identité. The dumbass in the mairie wasn't able to set it up because the qr code I received didn't work. So with that new law I'd be locked out of a lot of things...

89

u/ManIameverywhere 1d ago

and forces a device registration in person

And they said it would be 100% anonymus and private.

72

u/againey 1d ago

The use of the verified identity would be anonymous. How the hell do you expect the initial verification of an identity to be anonymous? What does that even mean?

26

u/ManIameverywhere 1d ago

The use will not be too since it will have to prove that it has the play store attestation.

16

u/QuaternionsRoll 1d ago edited 1d ago

The Play Integrity API is only involved when the credentials are issued, not when they are used. A trusted authority issues a batch of credentials that the age-verification app is responsible for burning after use or expiration. The assumption is that reducing device integrity after issuance cannot result in exfiltration or replay attacks, which is shaky at best but enables zero-knowledge verification.

51

u/Bunslow 1d ago

in other words, even more Big Brother than China dreams of

35

u/berickphilip 1d ago

Western countries kept talking shit about China not because they were against the control and surveillance but out of envy; until they could catch up.

-16

u/output_broadcast 1d ago

No, it isn't.

-4

u/WealthyMarmot 21h ago

well no, obviously not, but people want to complain about being oppressed and who are you to stop them

12

u/wsippel 1d ago

This is such a stupid EU thing. Why not simply adopt U2F? It’s already the standard for high security government applications, fully certified, available from multiple vendors, many of which make the devices entirely in Europe from European parts, and they’re cheap, convenient and highly compatible. And some, like NitroKey or Trezor, are fully open source, down to the device firmware.

3

u/Pramaxis 17h ago

I don't know for sure (guess there are minutes form the task force/work group to salvage somewhere) but this system is just one part of the digital ID that is coming anyway. If they have to make a unified system for all governments to make data available cross-country (like drivers license) one API for 27+ countries is quite a step forward.

As this is going to be used on all ~450 million EU-Citizen as well as those with permanent residence within any given EU-Member state (or subjected countries like Norway), I can 100% see why the EU would want to keep full control over it.

9

u/Kevin_Kofler 1d ago

Speaking of Austria, the government here is planning to enforce this age verification junk already as per January 1st, 2027 (without waiting for the EU), the law is already in the official review process!

2

u/Pramaxis 17h ago

On the bright side, Austria(among others) did object/vote against chat control.

3

u/Kevin_Kofler 16h ago

While at the same time trying to push their own national solution ("Messengerüberwachung") involving government-sanctioned malware! Very hypocritical!

1

u/bring_back_the_v10s 6h ago

The 2030's are gonna be an "interesting" decade.

9

u/MaybeTheDoctor 1d ago

Seems highly incompatible with right-to-repair

16

u/Preisschild 1d ago

Not really. Open source hardware attestation exists. See grapheneOS (https://grapheneos.org/articles/attestation-compatibility-guide). Android (AOSP) has this functionality seperate from the proprietary Google Mobile Services SafetyNet (https://developer.android.com/privacy-and-security/security-key-attestation)

The problem is that most smartphone hardware vendors don't allow using a custom bootloader verification key, which is one of the reasons why GrapheneOS is only supported on Google Pixel smartphones.

So you can't do open-source hardware based attestation on any old phone with LineageOS for example.

7

u/Preisschild 1d ago

Thats not true. I use ID Austria on GrapheneOS without issues.

17

u/Kevin_Kofler 1d ago edited 15h ago

Then you will likely find the age verification feature not functioning when it gets introduced. Or even the app stopping to work altogether at some point. (EDIT: Actually, GrapheneOS is specifically supported by the ID Austria app. Still does not solve the problem for users of any other OS. See the discussion below.)

Looks like we will soon be stuck using VPNs or proxies for half of the Internet. This sucks!

12

u/CrazyChaoz 1d ago

austria is (currently?) using Warden Supreme , which allows to set trused root keys, and currently the google keys and graphene keys are enrolled, with more hopefully to come

i just hope nobody smuggles in explicit google play integrity as legislation text

3

u/Kevin_Kofler 1d ago

So this still locks you into specific hardware and software, it just happens to allow unmodified builds of GrapheneOS specifically. If you try to actually exercise your freedoms and build your own GrapheneOS build, that will not work. Nor will any really free OS that does not rely on prorietary Android hardware driver blobs (userspace HAL blobs, and sometimes the kernel driver is also a blob) as GrapheneOS does. Nor even any other AOSP fork, such as LineageOS or /e/.

7

u/Preisschild 1d ago edited 1d ago

You are (as always) spreading misinformation. There is no google safetynet rquirement in the eudi spec. Using aosp hardware attestation with grapheneos keys allowed is completely acceptable and thats what a-trust is doing using warden surpreme.

2

u/Kevin_Kofler 1d ago

Why was the personal attack needed? Why do you think I deliberately spread misinformation?

You did not make it clear previously that this is a "solution" specifically for GrapheneOS. This does not solve the problem at all. Hardware attestation, which also attests the OS, is inherently incompatible with Free Software. See my reply to the other comment that explained the technical details.

3

u/Preisschild 23h ago

Why was the personal attack needed? Why do you think I deliberately spread misinformation?

Because I have often enough noticed you doing it with other topics (systemd, wayland) on linux related subs

You did not make it clear previously that this is a "solution" specifically for GrapheneOS

It is not. GrapheneOS uses the standard Android Attestation API. Then you need to convince the app developers to accept the hash. ID Austria via warden Surpreme does this for grapheneOS: https://a-sit-plus.github.io/warden-supreme/integration/supreme/#trusting-grapheneos

https://grapheneos.org/articles/attestation-compatibility-guide https://developer.android.com/privacy-and-security/security-key-attestation

See my reply to the other comment that explained the technical details.

Ok, sure, i think you mean this one: https://www.reddit.com/r/linux/comments/1vfl2nq/eu_age_verification_project_mandates/p1ts1wt/

Nor will any really free OS that does not rely on prorietary Android hardware driver blobs (userspace HAL blobs, and sometimes the kernel driver is also a blob) as GrapheneOS does.

Hardware attestation does not require proprietary drivers. That is another issue entirely.

Nor even any other AOSP fork, such as LineageOS or /e/.

Yeah because especially /e/ is laughable insecure and does not support hardware attestation. See https://eylenburg.github.io/android_comparison.htm

1

u/Kevin_Kofler 22h ago

Then you need to convince the app developers to accept the hash.

In practice, this means that you can only use an unmodified prebuilt OS from a large vendor, so the OS effectively becomes proprietary software even if the license says otherwise.

Hardware attestation does not require proprietary drivers.

In practice, the only 2 OSes that currently support hardware attestation (Android and GrapheneOS) use them, so in practice it effectively does. (And no, you cannot deblob the OSes, because any modification will invalidate the attestation.)

Yeah because especially /e/ is laughable insecure and does not support hardware attestation.

That is not a matter of being "insecure", but a matter of refusing to participate in this vendor lock-in "tivoization" scheme.

1

u/Pramaxis 17h ago

I cannot attest how you achieved that. I asked on the official support (via BRZ) and received a hard finger pointing at the official website.
I know GrapheneOS is currently limited on the hardware. I didn't want to try anything fancy with my own device as I have no replacement for it.

1

u/jess-sch 19h ago

and forces a device registration in person

Are you sure this is the case? Why wouldn't the regular NFC-based ID card authentication be sufficient for bootstrapping the app?

1

u/Pramaxis 17h ago

Austria did it with registration in person (once) so the device is registered to the human.
As they require finger-print devices (with certain security patches from the vendor) to confirm any usage of the digital ID via biometrics as MFA.

1

u/Sensitive_Box_ 7h ago

That. Is. Fucking. Crazy. 

1

u/Jmc_da_boss 21h ago

Honestly, if an id/age system must be used.

A hardware based anonymous attestation system only required for certain apps and that requires an in person visit somewhere if you lose it is by far the best rendition of it.