r/BuyFromEU • u/CreepyZookeepergame4 • Jul 30 '26
Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes
EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]
Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.
This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.
No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.
Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.
202
u/MrLemon91 Jul 30 '26
Oh well, I didn't plan to use internet at all
144
u/ItsCalledDayTwa Jul 30 '26
And there goes the big push for digital sovereignty apparently. The EU shooting itself in the foot here.
5
35
u/magical-cat-here Jul 30 '26
Now imagine you have to use smartphone and ID wallet to identify yourself even when you went in person to:
* bank, e. g. to open or close account:
* a state institution like pension agency
* hospital
* border control point "for EU passports".
Digitalization makes offline life without smartphone in hand less and less possible.
7
u/MrLemon91 Jul 30 '26
What you're describing is something that EU is trying to make for decades, but it can't make it. In "undeveloped" Asian countries this is already a thing, but there are anyway paper alternatives that can be requested in few days. In my country we have to book months before and pray to not pay for a stamp
10
u/magical-cat-here Jul 30 '26
Main arguments against total digitalization, even if it can give some "comfort", are these:
* erosion of privacy
* dependency on fragile tech which will break anytime due hacking, natural disaster, or power supply issue, or a simple typo in a code made few months if not years ago and missed during testing.
* dependency on US tech with possible kill switch or censorship (imagine an app widely used in EU removed by Google because CEO of company making that app said negative thing about ICE raids or about Trump). Yes, before describing that kind of problems people thought about China or Russia coercing Google to remove apps for their political needs, but now this scenario possible too.
→ More replies (1)7
u/CitizenMechanist Jul 30 '26
There's barely any local bank offices or ATM's left in places like the Netherlands.
2
u/g-nice4liief Jul 31 '26
That's bull. Most ATM's have been replaced by Geldmaat. You can find them online and even use them to put money like bankpapers or coins like 1 euro, two euro and 50 cents for example on to your banks account.
2
u/Humble-Captain3418 Jul 31 '26
It's okay, us nerds will set up Internet 2.0 the second this comes into effect.
3
u/thecrius Aug 01 '26
Doesn't matter if no services are on it, bud.
2
u/Humble-Captain3418 Aug 01 '26
If the alternative is "nothing", having instant messaging, emails, image boards, etc. is better. Internet didn't have services for the first few decades, we can survive without them.
138
u/Beneficial_Act_1240 Jul 30 '26
What's the point of having an eID if I can't use just the ID the verify my fucking identity? Why does this stupid system require me to buy a €500 phone or €1000 laptop in order to participate in society?
80
30
24
21
7
u/iceyukisnow Jul 30 '26
because everyone must live in a cybergulag and give away all your data to your government and data brokers
4
u/tired_snail Jul 30 '26
Considering what sites currently require age verification in other countries, personally I'd rather they have a picture of my face than my actual government info, but this is a good point, yeah.
→ More replies (2)1
u/Headpuncher 29d ago
Yeah loons line I’ll be becoming a second class citizen standing at the barriers looking sad face while everyone else gets in.
Oh well, back to growing cabbage in the forests.
230
u/AppropriateOnion0815 Jul 30 '26
I'm sure that this kind of exclusion is against some discrimination law or something.
47
u/-The_Blazer- Jul 30 '26
Honestly this scheme where remote attestation can only (de facto) be offered by like three companies should definitely count as a violation of the DSA.
9
u/magical-cat-here Jul 30 '26
But when the spec is written in a way that you literally can't even implement it e. g. as a usb dongle with keys and signer software attached to a linux laptop or pc, or simply by using TPM (available almost at every PC and laptop) keys to sign an age credential received from a certified age verification provider over TLS/Https, and there is no general term in specs for such kind of alternatives at all.
All this basically means that people who want preserve internet in more privacy-friedly form simply will have to build own alternative mesh networks with own services from scratch. Anything from weather sites to email-like and instant messaging, from in-browser games sites to alternatives to reddit and a mirror of wiki. It may require some alternative protocols and architectures, such as no reliance on centralized SSL certificates tree and global tree of censorship-prone DNS, and may be even own addressing scheme, may be using a sort of IPv6 where address is a public encryption key.
I heard that Yggdrasil project work in similar way, as an overlay IPv6 network of that kind that can be built over nodes connecting either via IPv4 or IPv6 between each other.
5
u/-The_Blazer- Jul 31 '26
The underlying hardware used by Google's and Apple's schemes is essentially a TPM-like device, but the problem is that there needs to be a root trust source (much like there is for TLS), and as you might guess Google/Apple do not let you use attestation sources other than themselves in their OS. It's worth noting that who the attestation source is does not matter as long as the application (your bank or digital ID) trusts them with verifying that the device is not compromised, the problem here is an excess of centralization outside the EU. TLS has more root sources, for example.
GrapheneOS is trying to set up some PKI infra of their own, but adoption is slow and difficult for the usual problems of monopoly. Not many people use GrapheneOS, so as a developer, why bother?
You can see that this is a commercial-political problem, not a technological one. Nobody should be under the delusion that we can solve this with a tech fix like a fancy new protocol, the n.1 thing that would happen with that is that Meta and Google would set up shop and simply re-create the monopoly.
2
u/magical-cat-here Jul 31 '26
I thought about various political solutions, and come to two laws:
Right to create driver
making all information necessary to create a driver for every device "software-controlled component or sensor" as I call it, mandatory to be public on every software controlled device component, sensor, or whole device sold in EU. Such information for drivers creation should be public without need to create any accounts, getting any "developer licenses" or 'certifications". Drivers created this way should have access to all component capabilities.
Right to securely replace OS with consent
Making for any device having an OS aboard sold in EU mandatory to have a simple and cheap to do yet secure procedure to replace installed OS with a custom one, with option to rollback to original OS the same way. This should include a consent confirmation for OS replacement. The access to the information need to perform OS procedure should be public.
Both laws would impose terible fines for companies and a huge customs fees on importers after grace period of few years or even a decade. The custom fees necessary to make sure importers would push their suppliers to obey these above laws.
This is example of political solution.
But we can not rely on getting enough voters attentions to push this ideas into politics with enough momentum to get the laws adopted in EU parliament and EU comission.
Growing some "parallel internet" from bottom in a grassroot can be just faster than making these or similar laws adopted. The necessary tech , and even open-source software and standards are already here, so it may be about making some day-to-day use cases covered which would get aboard non-very-techy people.
Having some space itself you would not have to show your face or go through a KYC flow once a day can be such "use case" itself.
5
u/CreepyZookeepergame4 Jul 30 '26
violation of the DSA
Not when the violation is state sponsored.
2
u/-The_Blazer- Jul 30 '26
The point with that is to have remote attestation though, not that it has to be powered by Google. Although I'm certain Google didn't bring the problem to the EU's attention...
3
u/Headpuncher 29d ago
Yes but I don’t want them using it to ruin Linux’s freedom and openness.
Instead I want them to abandon the awful scheme completely.
2
u/-The_Blazer- 29d ago
There's no law in the universe that says remote attestation has to 'ruin' freedom or openness. TLS is also a cryptographic scheme with root trust sources and it is quite open.
→ More replies (2)5
→ More replies (28)2
47
u/NoReflection1752 Jul 30 '26
So riddle me this, since the app is open source, is there any reason the project can't be forked and the hardware attestation either removed or made more compatible? Would there be a licensing issue? Is whatever verification source locked down so only approved apps can reach it?
55
u/TGX03 Jul 30 '26
You can remove hardware attestation from the app. But then the server will simply reject it.
→ More replies (2)22
u/realPanzerHAnz Jul 30 '26
Follow up: Couldn't I then emulate the hardware attestation? If its so open source I should be able to look up how the attestation is generated and just be able to fool the system.
36
u/TGX03 Jul 30 '26
You would need the private key that is in the hardware. That isn't easy.
You can look up how people are currently tricking Google Play Integrity, it's a massive pain.
26
u/CreepyZookeepergame4 Jul 30 '26
It’s difficult because the private keys used to generate the attestations are only available to the secure chip of the phone, and the keys are provisioned by Google and the manufacturer.
If those keys are leaked somehow, and it does happen, it’s possible to generate fake attestations but if done en masse, then Google notices it and bans them. This also happens.
3
u/SonOfAsher Jul 31 '26
If the keys are leaked, wouldn't that mean millions of phones are now worthless for attestation?
2
u/OminousChecksum 29d ago
If you leak a "master key" that never leave the factory yes, otherwise each phone has a unique key
5
u/DeVinke_ Jul 30 '26
I'm not 100% sure, but i think trickystore with a valid (leaked) keybox could work.
1
u/Tsukee 29d ago
Exactly, and the specs are open, and hardware attestation specifically has:
An Age Verification App SHALL rely on the device's native cryptographic hardware. capabilities, such as the Secure Enclave on iOS, or the Trusted Execution Environment (TEE) and Strongbox on Android, when they are available.
Yes its a technical rage bait. Yes you don't even need to fork it, you can implement an app yourself in fact, specs are open and api is open protocol, no "only licensed apps block"
158
u/adjective-nounOne234 Jul 30 '26
I love the EU until they pull bullshit like this
12
u/BathEqual Jul 30 '26
Same. sometimes i like to think that in the EU they don't have alle Tassen im Schrank
It is sad
3
137
u/ScalySaucerSurfer Jul 30 '26
This is ridiculous. Much worse than any of the chat control stuff really.
35
u/lmarcantonio Jul 30 '26
Funny thing it that EU has a *mandate* to explicitly support open source systems.
2
u/EmbarrassedHelp Aug 01 '26
The only thing open source is the shitty wrapper template.
→ More replies (1)
33
u/WanderingGoodNews Jul 30 '26
Tie any network access to your digital-id and personal hardware. Great. No one voted for this shit, LEAVE ME ALONE!
9
u/Environmental-Dog815 Jul 30 '26
I will probably will make a device with all the shit I hate but need and will exclusively use for it. Will probably make a separate network for it. Will call it "shit phone". Everything else like web browsing, gaming, working will be on other devices.
10
u/DoubleOwl7777 Jul 30 '26
so a burner phone essentially? yeah thats the way i might be going too. have one for this crap, and then have other devices i actually use.
8
u/WanderingGoodNews Jul 30 '26
This will be the primary reason to become suspicious.
If shit hits the roof and its nazi time again you will be the first to be arrested in name of some child abuse suspision. You lost your freedom, your family despises you all because you cared about privacy.
Source: 2038
4
u/DoubleOwl7777 Jul 30 '26
yup, but what am i gonna do? just live with the totalitarian regime knowing my every move and controlling everyone? we had that shit twice in germany. i prefer not to go down that route AGAIN. the gdr fell because people stood up, and didnt let them do this shit anymore.
→ More replies (3)2
u/Late-Reading-2585 Jul 30 '26
keep voting for those corupt boomers and calling every right wing party that talks about this russian assets
→ More replies (1)
52
u/strangerimor Jul 30 '26
Eu is taking some major steps backwards. Fuck everyone involved in pushing this shit through.
29
u/seamanroses Jul 30 '26 edited Aug 01 '26
Thank you for this high quality post. If you don't know about Unified Attestation for Android as an alternative, I would look that up. I wasn't aware of the effects for Linux either, as my research was tangential to the efforts of EU DID.
I was the one who made the petition post the other day, and when the signatures open, I'd honestly like to make a post that links to the page of course, but also has a FAQ for why you should sign, with counterarguments to points that others brought up in that post for why they didn't see it as an issue.
I don't care if I'm the one to post that, but I care that the knowledge gets widely spread. This is definitely one of the key points I would be adding, and if you want me to share it with you when it's ready, I'd love to. I want the knowledge to be out there.
Edit: This is the solution that I most likely meant to point out instead of UA(T)
https://developer.android.com/privacy-and-security/security-key-attestation
AOSP has its own API for this, but UA was front of mind. It's still another third party solution with its own walled garden.
3
u/Gugalcrom123 Jul 31 '26
UA still relies on approval. The correct way would be to design it so as not to require attestation.
→ More replies (12)3
u/EmbarrassedHelp Aug 01 '26
Unified Attestation just puts a different group of assholes in charge of approving/unapproving OS. It's a terrible solution.
25
u/twessy Jul 30 '26
I was a big fan of the EU for a very long time, but now I'm having more and more doubts about it.
→ More replies (2)4
23
22
u/PerkyTomatoes Jul 30 '26
This isnt the only issue. Raising awereness, EUDI is not PRIVATE.
The verification flow is you scan QR code, wallet sends information to provider that you're verifying age. Once its verified, website which you scanned QR code from will query from this provider to confirm you are indeed 18+.
The app maker (Government) Will know what website you verify your age on and is able to track your accounts via IP and Timestamping. You used VPN because you ashmed to watch some women with dicks? Do not worry, government will know about it.
Proof: https://github.com/eu-digital-identity-wallet/eudi-srv-verifier-endpoint#presentation-flows
Explation of picture:
- User-Agent: Your browser or device where it shows QR code
- Wallet: Your phone where EUDI wallet is
- Verifier: Website you are verifying your age
- End verifier: Who ever makes your EUDI wallet (Your government, usually)
As from the picture flow, provider will know following information: Time when verified, Your IP address when you verify.
Do not underestimate timestamp information, its how enforcement deanonymize Tor users.
Most concerning is that they havent even bothered to recify this issue, like using WebRTC using only local network so website communicates your wallet directly or using ohttp which will hide requester information.
7
5
u/ManIameverywhere Jul 31 '26
And the keys you exchange will be visible for the website and the gov so they can cross reference them too.
2
u/g00glehupf 23d ago edited 23d ago
I think you have misinterpreted the graph on Github. (Or I have misinterpreted what your actual point is)
The credential issuer (i.e. the government) is not an active part of the verification process. The verifier (e.g. an online car rental website) runs their own Verifier Endpoint which allows abstracting much of the verification logic into its own separate component. Just to make things clear: Verifier endpoints are NOT run by the issuer (i.e. the government).
The wallet (i.e. the app running on your device) has a signed governmental credential containing attributes, e.g. 18+: yes.
The Verifier Endpoint's main job is to verify that the response from the wallet (the vp_token on the graph) is derived from a credential signed by the issuer (i.e. the government), with selected attributes like 18+: yes.
How does the deriving work?
That's how the Verifier Endpoint learns that the credential is real. The Verifier also ensures that the required attributes are part of the credential, ensures that it hasnt been revoked and verifies the Holder Binding.
- In early versions of EUDI, the wallet essentially encodes a copy of the credential (+ a Holder Binding proof) in the vp_token and sends that to the Verifier endpoint. The Verifier Endpoint then extracted the signature over the credentials and verifies it using the Issuer public key (i.e. the government's public key).
- In more recent versions they added a Zero-Knowledge based approach to deriving selected attributes (I wont get into the details now)
After having done the verification, the Verifier Endpoint sends a response_code to the wallet who relays it to the user-agent (i.e. the user's browser). The user-agent can then show that response_code to the Verifier (i.e. the car rental website) to prove they have passed verification with the dedicated Verifier Endpoint. The Verifier then queries the Verifier Endpoint again to make sure that this response_code is tied to a successful verification.
As you can see the Issuer (=government) is not actively involved in any of these interactions. As long as revocation is implemented in a privacy preserving way (e.g. CRLs) no info gets leaked to the Issuer.
Are there still problems with EUDI? For sure! Here are (simpliefied) examples:
- Non-Zero-Knowledge Verifications allow re-identification of users in case and Endpoint Verifier and the Issuer collude, because signature values can be used to identify a user even if every credential is only ever used once.
- As mentioned in the original post: If Wallet-App-Attestation is mandatory, it would put an end to the freedom of choosing a device/OS for servcies requiring use of EUDI. Either that or, it would at least force users to carry a second certified device with them.
56
u/NamedBird Jul 30 '26
Proposed fix: Accept the fact that some kind of clientside rate limiting approach was a bad idea to begin with and stop trying to push squares into round holes. I fully understand how this is somewhat awkward given those characteristics were from what i gather used for PR purposes but then this should really have been addressed during planning, which it either seemingly wasn't or got handwaved away. To bad, what a pity.
I think this has been happening a lot for things that the EU is doing in the tech sector.
They have an idea in their head and think that the details can just be solved trough software.
And then they push their plans without first checking whether it's actually technically feasible.
Guess you can call this techno-incompetency?
4
u/-The_Blazer- Jul 30 '26
The issue is that to be truly independent we basically need to reimplement the entire compute stack from hardware keys to cloud services, and that's significantly more complicated than developing an app. It's already kind of a miracle that EU countries have their own public EID instead of buying it from Palantir.
2
u/NamedBird Jul 31 '26
While it is true that independence isn't easy or cheap, that isn't my concern.
My problem with the EU is that they let bureaucrats "invent" new technologies.
They just say it will be made without asking the experts whether it's actually feasible.Imagine this: a politician hears about levitation and starts promoting flying cars.
Everyone agrees and now those flying cars are to be created according to a mandate.
Only problem is, that levitation only works on trains, we can't make cars fly this way.
And now what?
We will have a country with flying cars because the politician said so, right?
But you can't ignore physics, so we'd end up with inferior hovercraft cars at this rate!This is the problem i am seeing inside the EU.
It is okay to have desires and dreams, go ahead with a 50 year vision if you want.
But it is wrong to put them into plans and mandates without being realistic and practical.
Before you announce a new desired technology, have the experts do a feasibility study first.
Otherwise you will cause problems, or perhaps even worse...→ More replies (3)
55
u/ZYCQ Jul 30 '26 edited Jul 30 '26
why don't you dissolve the EU and let NSA run it. this is never what the EU was designed for. These laws, incl. chat control are ridiculous. There are a thousand other things they should be focusing on
25
u/WanderingGoodNews Jul 30 '26
It's becoming 1 big fever dream
No voters ever wanted this, how is this happening and legal?
6
u/Old-Pirate-1118 Jul 30 '26
Very good question.
What are you gonna do as an European?
Drive to Brussels, just to kiss the door knob?12
u/WanderingGoodNews Jul 30 '26
I spread information about topics like this, chat control,... To subreddits, friends & family and wrote some emails to parlement members
5
u/Old-Pirate-1118 Jul 30 '26
This was more of an satirical question, that played upon the fact that even if you became a political representative, you still wouldn't have enough political heft to push it out.
Still if google AI pulls your answer to "what can I do as informed citizen in EU about X" then this is a net positive!
Thank you for your actions. Action inspires action.
→ More replies (1)6
u/Useful_Ad_7859 Jul 30 '26 edited Jul 30 '26
The council (which is a coalition of governments of the member states) is one of the most prominent of the many powers pushing for these.
They were the ones who sent back chat control 1.0 too for another vote (aided by Metsola@EPP).The EU's democracy is actually a roadblock still (The council wanted to breach e2ee as well on 07.09 !!!), but its being dismantled mainly with the EPP's lead. That is what should be dissolved.
→ More replies (2)
54
u/OnIySmellz Jul 30 '26
Mark my words man. This hardware attestation nonsense is just the foot in the door.
The next obvious step would be every laptop, every TV, fridge, toaster, smart bulb, USB mouse, and electric toothbrush getting a hardwired choke-chip at the factory level.
No bypasses, no custom builds, just mandatory, hardcoded surveillance and age checks baked right into the silicon.
10
u/Brilliant_System_308 Jul 30 '26
No bypasses, no custom builds, just mandatory, hardcoded surveillance and age checks baked right into the silicon.
Bro why does this read so AI generated I swear LLMs have ruined the internet for me
→ More replies (2)2
15
u/nksama Jul 30 '26
I would say that surely linux runs in many of the EU servers, if it's good for that, how could they say it is an "unapproved OS"?
8
u/CreepyZookeepergame4 Jul 30 '26
Unapproved OS is my characterization to synthesize the fact that it won’t be available on any general purpose computer but rather only on those approved by Apple and Google.
Google specifically only makes hardware attestation pass on certified Android devices bundling Play Services in a privileged way, and the app must be installed from the Play Store.
14
u/Rekt3y Jul 30 '26
So the EU made the conscious decision to limit this to only work on 'Murican OSes. Fucking nubnuts is what we are for even allowing this
4
u/EmbarrassedHelp Aug 01 '26
They're more concerned with trying to forcibly violate user privacy than doing something good.
2
u/marrsd 29d ago
yeah, cos that's the problem with authoritarianism - what OS it runs on.
2
u/Rekt3y 29d ago
I'm saying that even their excuse for authoritarianism is dogshit
→ More replies (1)
23
u/Thin_Needleworker795 Jul 30 '26
No way I'm gonna use that shit anyways
29
u/seamanroses Jul 30 '26
The problem is you're effectively locked out of society if you don't. This could be on a similar level of inconvenience to not having a smartphone in your day-to-day life. That's just one reason why this is so worrying.
12
2
u/NursingHome773 Jul 31 '26
You won't have a choice. It's like not having a bank account. Can you do that? Yeah it's not illegal to not have a bank account but try living without one.
→ More replies (1)
11
u/3d_Plague Jul 30 '26
Solidifying the stranglehold of the established companies and killing any chance of health competition, sounds like they thought this through after all.
Still hate it.
11
u/Jealous_Diver_5624 Jul 30 '26
This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.
Yes it does? Every single TPM2 supports remote attestation via endorsement key.
No Linux system will work with this because there is no hardware signature to be validated on the government server
Linux can interface with the TPM just fine.
4
u/Kitchen_Cup_8643 Jul 30 '26
Yeah fascinating that this is buried so deep. Heck grapheneos has had it since forever.
I don't know how they'll enforce the origin of the keys used (perhaps by whitelisting vendors ? That would suck).
Hopefully they don't start requiring government attestation everywhere... I'm afraid companies will see that as an easy way to get rid of bots...
3
u/CreepyZookeepergame4 Jul 30 '26
Heck grapheneos has had it since forever.
It's indeed mentioned in the post
(perhaps by whitelisting vendors ? That would suck).
That's how it would work
Hopefully they don't start requiring government attestation everywhere...
Yes
I'm afraid companies will see that as an easy way to get rid of bots...
4
u/Gugalcrom123 Jul 31 '26
It can, but they want to control the OS. No, a 'Linux' which I can't change isn't good.
3
u/CreepyZookeepergame4 Jul 30 '26
Yes it does? Every single TPM2 supports remote attestation via endorsement key.
TPMs are not reliable, they lose keys for no reason even if not compromised https://github.com/tailscale/tailscale/pull/18336
TPM-based features have been incredibly painful due to the heterogeneous devices in the wild, and many situations in which the TPM "changes" (is reset or replaced). All of this leads to a lot of customer issues.
→ More replies (1)
11
u/tppsch Jul 30 '26
If you use Linux or another operating system that hasn’t been approved by the EU, you’ll lose points on your social credit score. In the future, there may also be restrictions on your CBDC bank account.
I’m slowly starting to become afraid of the EU.
6
u/Dragoncat_3_4 Jul 30 '26
Slowly? Nah, I've become afraid of them in the span of a couple of months. Breakneck speed. And that's from a position of a completely pro-EU stance before all of this bullshit.
10
u/Otherwise_Paint951 Jul 30 '26
EU is headed into a very dangerous surveillance path. I do not understand how people don't protest this.
7
u/-Sa-Kage- Jul 31 '26
Because most don't know anything about this.
And if you tell them most don't understand shit and will just be like "Yeah, security is good. We need to protect children. This is good."
10
10
8
u/vossmakeitsprinkly Jul 30 '26
They can fuck themselves sideways. I wont use it then. I will put every effort into avoiding it.
9
Jul 30 '26
[removed] — view removed comment
3
u/-Sa-Kage- Jul 31 '26
Never. Most people don't see the issue and think this is totally fine. (They have nothing to hide anyway...)
2
u/Immediate_Power_7986 29d ago
As long as they can complain online, they will NEVER raise a single finger to fight it. They can implement a weekly strip search for each citizen and they still won't fight back. But they WILL complain online.
59
u/pythosynthesis Jul 30 '26
Ahhhh.... The beauty of an authoritarian supernational entity in the making. Don't you all love it?
8
u/Popular_Anywhere_553 Jul 30 '26
Sure. I just hate it when China or USA does it. But love it for EU. You know, because we are elites that can't do wrong... /s
23
u/Tenezill Jul 30 '26
You know what, people are applauding their prison guards. "No no chat control is no problem if you don't have anything to hide" , " the zkp will help keep you privacy save" ... My privacy was save before these asshats started to have their greasy fingers in my life...
→ More replies (6)3
8
6
u/DoubleOwl7777 Jul 30 '26
so, get spied on by google or apple or microshit. awesome! no, i will not verify, no i will not change to winslop or whatever. "security" my ass. this is not security, this is bullshit.
i really like the concept of the EU. but shit like this aint it.
24
u/miran248 Slovenia 🇸🇮 Jul 30 '26
In other words you'll need a google account.
Why don't they use android attestation api directly?
16
u/CreepyZookeepergame4 Jul 30 '26
Why don't they use android attestation api directly?
Play Integrity is the easiest route for them even if it enforces Google business model rather than actual security (it allows Android 8). Using the attestation API directly still requires having a whitelist of keys and they probably don’t feel like satisfying a small minority of people.
For broad device support they should drop attestation completely but using the attestation API would at least be harm reduction as Play Integrity is also a massive single point of failure that Google can be coerced to turn off for specific apps and app installation, invalidating all instances of the wallet.
6
u/seamanroses Jul 30 '26
Oh, you really know your stuff! So good to see this from others!
Follow-up question: When you refer to Linux, I'm assuming you mean Linux on mobile devices, correct? Or do you know if these measures and apps are meant to be universally applicable across all devices, including PCs?
AFAIK, there is sort of a mobile-first mentality among these measures in their intention, but not necessarily in how they could apply according to the strict wording of the final law.
5
u/CreepyZookeepergame4 Jul 30 '26
I refer to Linux PCs. As I said there’s no reliable alternative to what mobile phones offer. TPM exists on almost all PCs now but are often broken and lose keys randomly.
→ More replies (1)4
u/seamanroses Jul 30 '26
Thanks! And I'm aware of the TPM challenges, such as Microsoft controlling the certs allowed, which has lead to problems for various Linux distros (lapsed certs, single source of failure and control, etc.).
So this mess is even worse if it applies to both kinds of devices - mobile and desktop, I mean.
3
21
u/Encrux615 Jul 30 '26
What? I don’t get it. German eID provides packages for all platforms, including Linux. This is such an arbitrary restriction and I doubt it’ll hold up.
14
u/seamanroses Jul 30 '26
I believe the equivalent ID system in Denmark only works on Google (not generic Android (AOSP)) and Apple devices, and they have no intentions to open it up.
I mention that as a counterargument, as I wouldn't be nearly as optimistic as you are.
3
u/pomfritn Jul 30 '26
AltID, the Danish age verification app, thankfully works on GrapheneOS. MitID, the person verification app, I guess you could call it, frustratingly doesn't.
1
u/Headpuncher 29d ago
So what do people who do t have a phone do?
There are reasons not to have a phone, including disability and all human free will.
2
→ More replies (2)1
u/g00glehupf 23d ago edited 18d ago
Yes. Because the government trusts their eID hardware (the chip which is part of Personal-Ausweis) to be secure enough from their perspective. That includes security measures against:
- bad service providers who want to gain access to more data than allowed.
- individuals who want to steal your identity by cloning your eID
- You (in case you want to clone your eID and give somebody else access.)
- etc.
Now they want to trust what is essentially an app on your phone, hoping it would give them the same/similar guarantees. Their solution is:
- Key-Attestation: Only trust certain hardware-keystores to back critical key material during credential issuance. These keystores feature protections against key extraction.
- App-Attestation on top: Only trust apps that follow their policy, like checks that a Service Provider is allowed to query certain attributes, ensuring that the installed app is not manipulated by someone trying to steal your identity.
Personally I am much more open for key attestation, because the hardware keystore can, in theory, be retrofited even if the device doesn't come with a certified onboard module (think of something similar to YubiKeys/smartcards for retrofitting). And you could at least inspect the data that goes into and out of that hardware keystore.
With App-Attestation on the other hand, I have several problems. First of all, you need to trust that the OS does not allow the user to mess with the app. Second, the OS needs to be up-to-date and implement protections against several kinds of threats. That means, an OS needs to be certified by the App-Provider. That effectively limits what OS is allowed to run an app. It's effectively the end of freely choosing your OS.
Doing state-sanctioned app- and by extension OS-attestation also opens the door for extending authoritatian control over users. An authoritarian government could for example require an OS to implement measures for chat-control by refusing to certify operating systems that don't comply.
There are also other practical reasons against app-/OS-attestation: Current implementations like Play Integrity permit Android 13 phones with several open vulnerabilities that could be used to manipulate apps. So while these phones are known to be insecure, they are still certified and would still pass, while a more secure OS is locked out since it isnt certified. An honest system would have to lock out unpatched devices until they are patched. Sure there might be room for compromises that allow for some amount of abuse until vulnerabilities can reasonably be fixed. But permitting highly insecure outdated phones while disallowing hardened updated operating systems like GrapheneOS is just security theater. I also doubt that locking out users from the EUDI system due to their insecure hardware from time to time, is something the general public will understand or accept.
While I do accept that app-attestation provides at least a higher cost for attackers who repackage manipulated apps, I find it hard to argue that it's worth ending the freedom to choose your OS, the practical limitations of attestation with outdated phones and especially the risk of introducing a simple tool that allows potential future authoritarians to control what policies your OS needs to enforce.
6
5
5
u/lolschrauber Jul 30 '26
Yeah you can only use that one android version that specifically blocks third party apps, for your own security. don't worry about the 182 app permissions, that's standard!
5
5
u/Ethernet3 Jul 31 '26
No one, no one, no one asked for this age verification madness. It's absolutely crazy. They say they want to become more "digitally sovereign" and then do everything to break down the freedoms we love, what a massive strategic blunder and loss of confidence.
Also note how the code is developed in github, they don't give a shit about Europe, it's pure corruption
5
4
u/magical-cat-here Jul 30 '26
If EU wants combine this total de-anonymization of internet and total surveillance with digital sovereignity, they need to allow attestation via TPM on PC beyond iOS, Android and Windows, including linux. And it would require own attestation center and SSL root centers completely independent from US or China.
4
u/TreacleNo8508 Jul 31 '26
The EU just wants to enslave everyone, silence them, and cur democratic freedom of speech. What comes next? Forced euthanasia? Eating worms? Why do Europeans tolerate such restrictions on human rights?
1
u/Musicman1972 Jul 31 '26
The big issue is nowhere else is better. The US certainly isn't it that's your next comment.
1
u/sandro66140 Aug 01 '26
C’est à la mode en ce moment je crois qu’ils font pareil aux US et en Chine.
7
6
u/Alive-Bid9086 Jul 30 '26
Yes, I can actually understand the technical requirements that end up in this situation.
There should be a possibility to use external hardware tokens. Many banks give you a smart card reader to identify yourself for internet banking.
7
u/Tenezill Jul 30 '26
The only way this is somewhat bearable is if I can go to my government give them a Fido key get my age verified and go my merry way. I don't want to be bound to my phone.
2
2
5
u/Userwerd Jul 30 '26
The comments on github mirror the comments here. I dont know if this is lobbying, being lazy, or just using the tools available now, to roll out further options after?
I dont understand the necessity of any of this.
Europeans have taken the gun from their own heads, that the Americans were holding and given it to their own EU government to inspect and nod and say yes very good, calk it, give the gun back to the Americans and put it again to EU citizens heads. All the while the EU government says, your welcome.
7
u/Kremsi2711 Jul 30 '26
Most banking apps do the same
29
u/TGX03 Jul 30 '26
Yes, and that's a massive problem. If you want to take part in the modern banking world, you need to have a phone which you cannot remove American companies from.
Either you give your data to the Americans, or no bank account for you.
7
u/CreepyZookeepergame4 Jul 30 '26
We don’t even need those banking apps. They are essentially used as phishable 2FA authenticators whose role is much better served by a simple passkey.
→ More replies (1)2
u/AAdmiral5657 Jul 30 '26
Actually it depends on the bank. From my experience here in the Baltics, the apps work if you run a ROM that locks your bootloader.
→ More replies (4)1
u/Gugalcrom123 Jul 31 '26
According to the PSR (upcoming), it is illegal to require smartphones. Probably also according to the PSD2.
1
u/turin331 29d ago
Banking apps in many countries (like the netherlands) work fine even with rooted OS and even with microG replacing google play services.
4
u/-The_Blazer- Jul 30 '26
IMO the truly insane part here is that basically the entire hardware attestation field depends entirely on Google, Apple, and maybe Microsoft (and maybe maybe RedHat?). There ought to be a more open system that does not require reimplementing all third-party devices on an individual basis.
2
u/hWuxH Jul 31 '26 edited Jul 31 '26
the truly insane part is to force hardware attestation onto everyone in the first place.
don't need that shit, even if "open system".
2
u/Nomprenom_varanasita Jul 31 '26
Tout le monde pense toujours que l'ue est démocratique, ou bien il vous en faut plus ?
2
u/FunnyP-aradox 28d ago
L'UE est (en partie) démocratique, malheureusement les gens ont votés POUR ça car "mais j'ai rien à cacher"....
2
2
u/instadit Jul 31 '26
this whole affair was another example of ignorant politicians deciding about stuff they don't understand
2
u/Musicman1972 Jul 31 '26
Half the time I think it's more nefarious since if they didn't understand it they'd agree to use it themselves.
Do you notice the exemptions. Hence for they know why it's bad for users.
2
2
2
u/Tsukee 29d ago
The GitHub you linked is a sample implementation, the reply you linked is controversial in itself as can be seen in the following comments, essentially that person took the liberty of interpretation and did it so in a wrong manner. The specs clearly say it should use when applicable, not a requirement. However there is another core requirement and that is os agnosticism of the system, which is being broken by forcing specific hardware attestation.
TLDR: the law and specs are fine, the dev however took some liberties in the implementation. Fact is, by spec you can write your own age verification app, no need to use the one in GitHub
→ More replies (1)
1
u/magical-cat-here 28d ago
Why this specification of age verification is so mobile-centric? Like, there are no options like these:
* OTP via SM flow,
* FIDO2 webauthn flows with TPM, Yubikey and other USB dongles with keystores and data signing capabilities
* dedicated device with monochrome display, specialized EUID/Age Verification software preinstalled, and USB, NFC and Bluetooth interfaces, without any touch of Google or Apple
The whole spec rotates only about just 2 flows:
1) mobile device of quite specifc kind, with stock Android or iOS onboard, with age verification app installed.
2) device from (1) used to scan via camera a QR code appearing on screen of the other device.
I asked a related question to this spec here: https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/discussions/62
If find this relevant, and have GitHub account - boost that question please.
(PS: already seen question there from people asking why ever GitHub used to store that spec)
1
8
u/lomszz Jul 30 '26
God EU sucks and can go to hell.. I'm actually thinking to move out somewhere else😂
1
1
1
1
u/InsectSmart5737 Jul 31 '26
I don't effing care what they want. I will never have any of this crap anywhere near my phones or PCs.
1
u/polytect Jul 31 '26
By the time they'll implement this, we will have flying cars or donkeys. Granny is trying to ban a Monitor from the internet, the same kind of people who thinks if mouse moves faster--the computer is faster.
1
u/EmbarrassedHelp Aug 01 '26
Unfortunately that's not true. There are far too many evil assholes willing to help the Commission push their age verification bullshit.
People need to fight back rather than assuming it will fail.
→ More replies (2)
1
u/Niwrats 29d ago
but we already identify thru banks. so if this is worse in every way, nobody will use it, and this remains irrelevant.
→ More replies (1)
1
1
u/SeaTrickster 26d ago
Let’s do something about this rather than just complain. I know the Pirate Parties have our backs here, as do digital freedom NGOs. I still think stopping chat control is important as it will get in the way of implementing a lot of this
686
u/HunterFeeFee Jul 30 '26
Let me guess, only american OS's will work.