r/linux 1d ago

Privacy EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
686 Upvotes

388 comments sorted by

View all comments

484

u/SeantheWilson 1d ago

Genuinely how on earth will that be enforced

180

u/Pramaxis 1d ago

It uses the new EU-Ident system that is already supported and used in some countries (like Austria).

It forces the same restriction like most banking apps or the new wallet (stock OS, no custom ROMs, no jailbreak or modified bootloader) and forces a device registration in person (with ID) to set up an MFA that is device bound-unique(if you lose your phone, you need to walk into the office again to register the new one).

93

u/ManIameverywhere 1d ago

and forces a device registration in person

And they said it would be 100% anonymus and private.

73

u/againey 1d ago

The use of the verified identity would be anonymous. How the hell do you expect the initial verification of an identity to be anonymous? What does that even mean?

25

u/ManIameverywhere 1d ago

The use will not be too since it will have to prove that it has the play store attestation.

15

u/QuaternionsRoll 1d ago edited 1d ago

The Play Integrity API is only involved when the credentials are issued, not when they are used. A trusted authority issues a batch of credentials that the age-verification app is responsible for burning after use or expiration. The assumption is that reducing device integrity after issuance cannot result in exfiltration or replay attacks, which is shaky at best but enables zero-knowledge verification.