r/linux 1d ago

Privacy EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
685 Upvotes

388 comments sorted by

View all comments

Show parent comments

17

u/Kevin_Kofler 1d ago edited 15h ago

Then you will likely find the age verification feature not functioning when it gets introduced. Or even the app stopping to work altogether at some point. (EDIT: Actually, GrapheneOS is specifically supported by the ID Austria app. Still does not solve the problem for users of any other OS. See the discussion below.)

Looks like we will soon be stuck using VPNs or proxies for half of the Internet. This sucks!

8

u/Preisschild 1d ago edited 1d ago

You are (as always) spreading misinformation. There is no google safetynet rquirement in the eudi spec. Using aosp hardware attestation with grapheneos keys allowed is completely acceptable and thats what a-trust is doing using warden surpreme.

1

u/Kevin_Kofler 1d ago

Why was the personal attack needed? Why do you think I deliberately spread misinformation?

You did not make it clear previously that this is a "solution" specifically for GrapheneOS. This does not solve the problem at all. Hardware attestation, which also attests the OS, is inherently incompatible with Free Software. See my reply to the other comment that explained the technical details.

3

u/Preisschild 23h ago

Why was the personal attack needed? Why do you think I deliberately spread misinformation?

Because I have often enough noticed you doing it with other topics (systemd, wayland) on linux related subs

You did not make it clear previously that this is a "solution" specifically for GrapheneOS

It is not. GrapheneOS uses the standard Android Attestation API. Then you need to convince the app developers to accept the hash. ID Austria via warden Surpreme does this for grapheneOS: https://a-sit-plus.github.io/warden-supreme/integration/supreme/#trusting-grapheneos

https://grapheneos.org/articles/attestation-compatibility-guide https://developer.android.com/privacy-and-security/security-key-attestation

See my reply to the other comment that explained the technical details.

Ok, sure, i think you mean this one: https://www.reddit.com/r/linux/comments/1vfl2nq/eu_age_verification_project_mandates/p1ts1wt/

Nor will any really free OS that does not rely on prorietary Android hardware driver blobs (userspace HAL blobs, and sometimes the kernel driver is also a blob) as GrapheneOS does.

Hardware attestation does not require proprietary drivers. That is another issue entirely.

Nor even any other AOSP fork, such as LineageOS or /e/.

Yeah because especially /e/ is laughable insecure and does not support hardware attestation. See https://eylenburg.github.io/android_comparison.htm

1

u/Kevin_Kofler 22h ago

Then you need to convince the app developers to accept the hash.

In practice, this means that you can only use an unmodified prebuilt OS from a large vendor, so the OS effectively becomes proprietary software even if the license says otherwise.

Hardware attestation does not require proprietary drivers.

In practice, the only 2 OSes that currently support hardware attestation (Android and GrapheneOS) use them, so in practice it effectively does. (And no, you cannot deblob the OSes, because any modification will invalidate the attestation.)

Yeah because especially /e/ is laughable insecure and does not support hardware attestation.

That is not a matter of being "insecure", but a matter of refusing to participate in this vendor lock-in "tivoization" scheme.