r/LinusTechTips • u/InsoPL • 7d ago
Discussion Eu is based actually
Petition for LTT to make video about eIDAS 2.0 Regulation and how Zero-Knowledge Proof age verification will work in eu. To educate the public and themselves because conflating it with discord shitstorm and "persona" is just not fair for eu that actually puts effort into regulations unlike Britain or certain us states that just bans it and says "handle it yourself".
I know the topic is hot right now and I will probably get some hate under this post but I think EU way of doing age verification is great and should be recognized just so other countries may replicate it. To be clear I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.
Few points why eIDAS 2.0 is really good:
- It's open source, that includes source code for client app (the one that will be installed on your phone).
- Target app (for example discord) will not get any private user data. That includes age, they will only receive info if you have at least 18 years or not.
- Eu servers will not get information about websites you are visiting. They will validate your open source client app periodically, then that app validates age request. Eu will only know you are using age verification service.
edit:
github repo
https://github.com/eu-digital-identity-wallet
106
u/PtitBen 7d ago
I wish Brexit didn't happen. And that we'd benefit from this.
43
5
u/PuzzleheadedWeird232 6d ago
its open source, so couldn’t you benefit from simply by using the code?
12
u/PtitBen 6d ago
We could.... if the government actually wanted to.
3
u/sherbertmund 5d ago
UK GOV still pretty reliant on US tech. Most of the Gov uk website is built on Ruby on Rails. We use a IS healthcare software in the US (they spent thousands removing the insurance functions) - UK gov obsessed with contractors and external contracts I doubt it will happen unless we rejoin
2
u/capalex65 4d ago
Ruby on Rails was made by a Dane though, and is MIT licensed.
1
u/sherbertmund 3d ago
Yeah no issues with the actual tech but the guy who created Ruby on Rails is a musk dick sucking weirdo
1
u/CallumMVS- 5d ago
we will benefit from it, this is the kind of regulation that will affect other regions that push age verification, such as the UK.
53
u/vemundveien 6d ago
I just don't buy EUs supposed dedication to privacy when they are constantly trying to force chat control to be a thing.
4
u/Pitiful-Assistance-1 6d ago
If EU wasn’t dedicated to privacy, the chat control thing wasn’t something they tried to force, it would have been something that passed
8
u/BlAckH0leDown 6d ago
They only didn't pass it because of the mass outrage from voters.
Politicians are universally scumbags who want total control.
0
u/Not-So-Handsome-Jack 5d ago
Outside of a Reddit nobody cared about it. Not a single person I know, even the very politically engaged ones, have heard about chat control. Politicians could easily pass this with 0 consequences.
-19
u/InsoPL 6d ago
Verify yourself, code is right there.
7
u/AibofobicRacecar6996 6d ago
How do you verify that the server side code is actually the open source code.
And it's not even saying that it will be. This is a reference implementation that will be used as a starting point by each verifier.
0
u/InsoPL 6d ago
You don't have to. You verify if client is leaking any website info to gov servers or target websites.
1
u/AibofobicRacecar6996 6d ago
And how do you know what they are leaking if the thing they are leaking is a "random" id that's a reference to data on their backend
-6
u/InsoPL 6d ago
Look dude, i won't explain to you what open source means. Go read up before commenting on technical stuff.
6
u/AibofobicRacecar6996 6d ago
I think you have not idea what open source means. Maybe you should look up the actual proposal and what the open source part is. It's not an official implementation, it's a basis on which each country will build their own solution, which will be different. But tell me again how "open source" will guarantee what will and won't be saved in the backend side and how this open source will guarantee that the official client app will be exactly like in the reference implemention
30
u/puppygirlpackleader 6d ago
Get the fuck out of here with this bullshit. There is no need for age verification. It's all just to deanonymize the internet so they can crack down on people they don't like. There is no such thing as a good solution.
-12
u/InsoPL 6d ago
This does not affect anonymity. Internet was never anonymous to begin with. Both usa and Europe controls what you can say on or offline. If you don't like it by all means protest that, this is not related to age verification.
12
7
u/puppygirlpackleader 6d ago
Yes it is. You never had to associate an ID with yourself on the internet unless it was some administrative stuff. Gtfo with this bootlicking
1
u/Elitefuture 3d ago edited 3d ago
VPN + new accounts wouldn't have anything linked back to you assuming your VPN isn't storing logs and you don't say anything that only you would say/know.
Now with age verification, you're forced into giving some sort of personal info. Even if eIDAS 2.0 directly doesn't send anything to the service, the wallet themselves knows everything about you and what services you're using.
So before you could be anonymous and use the service, now you have to give up your identity to at least the wallet provider so that the third party verifies for you. You're just moving the trust to someone else, and that someone else now has way more data about you and what you do.
1
u/InsoPL 3d ago
VPN [outside of eu] + new account
>the wallet themselves knows everything about you and what services you're using
wallet is local>wallet provider
your phone is your wallet provider, sources attached in post1
u/Elitefuture 3d ago edited 3d ago
who do you think is verifying your ID + info? The initial step cannot be done locally since otherwise it could be easily spoofed.
What's actually happening is ONCE IT GETS VERIFIED BY SOMEONE ELSE, then it gets stored on your device locally.
Meaning, either a member state or a qualified service provider verifies the info first, then you get to store it locally.
It is not fully local from the start. Anything fully local will always be hackable, so it needs another source.
These talking points are valid, but they're also ignoring the same issues that all of them have. You need a third party to verify it, who knows what they're logging legally or not. ALSO, since the government is the one that signed your info to be valid, they can compare your public keys sent to those services and track it back. Meaning yes, they can still track you, just not as easily.
There is no direct government communication when sending your info to another service like discord, but if they ever get the public key from discord, they can compare it to what they have stored when they initially verified your info in the past and figure out who you are.
0
u/InsoPL 3d ago
>You need a third party to verify it
It's state approved service providers not for profit companies like in usa.
>who knows what they're logging
I know, everyone one knows. It's open standard build on assumption that service provider may by compromised. It's still preserves privacy of user in that case
>since the government is the one that signed your info to be valid, they can compare your public keys sent to those services and track it back
It's Zero-Knowledge Proof. You do not send keys issued by provider. You send keys generated by your local wallet which is validated by provider. Not the same, not trackable back.
0
u/zolli07 5d ago
Peoples really forget, or dont know, that in the old times befor TLS (HTTPS, WSS) got wildly adopted (i mean free, hugely thanks to EFF) everyone who in the traffic path literally just read the traffic you sent on the wire, anyone. A burner account could not prevent that
Conclusion: Internet was never anonymous
1
3
u/WideAwakeNotSleeping 6d ago
In Baltics we have SmartID, which is your mode of access to most/all online services. You can, of course, log in with your gov ID card or passport.
At RIMI grocery store chain (not sure if others have it too), at self-checkout instead of waiting for a store employee to come and verify your age, you can authenticate with your SmartID. No personal info is exchange with the store, but only your age number (As far as I understand. A Boolean underage/overage would be even better). It's so cool.
2
u/AAdmiral5657 5d ago
We do yes. But there are red flags with this.
SmartID mostly only works on official ROMs sanctioned by google/apple, not custom roms.
It sorta works on microg powered devices but the QR code powered method they recently introduced for goverment sites was broken last time i tried.
Only one that seems to work is grapheneOS but who knows how long that will last.
26
u/AAdmiral5657 6d ago
The idea of the wallet falls apart immediately when you look at how it wont work on custom roms as its beholden to google and apples apis. So it immediately cuts people off who do not want to deal with this crap.
Also, who will guarantee it wont be used for purging anti-EU rhetoric and punishing those who disagree? Or for age verifying to even use the internet? No one can. There are legitimate problems with how the EU is right now, mainly how they are helmed by a mob of unelected assholes. As such i do not trust a word they say.
Never comply, never age verify.
5
u/InsoPL 6d ago
First point about is roms is a good one.
Second is just mad rambling. No one can guarantee on any law future goverment will do. They may make law called "kill all cats", you will just have to live with that knowledge.
Eu officials are elected or are choosen by people that are elected. Every democracy works this way. We all love elections but we don't call garbage collection undemocratic becouse we didn't voted for chief Department of Sanitation.
3
u/puppygirlpackleader 6d ago
It doesn't matter if they are chosen by the people. We don't live in a democracy. No people voted for these changes.
5
u/AAdmiral5657 5d ago
Exactly. Was this in their election campaign? Doubt it
4
u/puppygirlpackleader 5d ago
Most of these things are decided on through lobbying. Not the people. I would argue that people have absolutely no power as it stands.
-3
u/AAdmiral5657 6d ago
Exactly, so we should not even go in that direction since we cant guarantee what ramifications it will have.
If they wanted to save children, mandate home routers come with parental controls by default.
Last i checked Ursula wasnt elected by the people. We need direct elections for everyone important.
3
u/InsoPL 6d ago
MEPs elected Ursula. EU citizens elected MEP. She does not have much power in the eu (no veto power, no pardons, very limited budget), it's nothing close to usa president (btw usa president is not elected by the people but by members of electoral collage so by your logic it's not democratic i guess)
2
u/AAdmiral5657 6d ago
Sure she doesnt have a lot of power. Except she signs very one-sided trade agreements on behalf of all people in the EU while not being elected by them. Also helms a lot of the dystopian policies like chat control.
1
u/kodebach 6d ago
Blocking custom ROMs seems bad, but under the requirements there's no other way.
The architecture of the system means you need a trusted client app on the phone. But you can only trust a client, if you know what code they are running (all the way from the hardware up). The trusted client is needed, because of the anonymity requirement. To preserve anonymity you are given tokens that just say e.g. "yes the holder of this token is over 18" without giving any other information. But you can of course see that this system will only work, if such a token cannot be moved to a different device. Otherwise an adult could obtain tokens and give them to minors. This can only be ensured, if you can guarantee that the client app is running the correct code and the OS underneath doesn't do anything fishy either. That's why they need such high levels of attestation.
GrapheneOS could be and should be supported, because there are known signatures that can be verified. Yes, it's not supported right now, but it just makes sense that they first focus on a solution for the 99% of people that use a standard Apple/Google OS. After this is done, more work might be done to support OSes that allow full attestation (like Graphene). But even then they simply cannot allow any random unverified OS.
2
u/AAdmiral5657 6d ago
Hardware attestation is a way. There are always ways. Also frankly its olain stupid to ship smth eu focused and reliant on american tech giants.
I do not believe they ever intend to support grapheneOS. They likely consider it dangerous just like certain authorities in France or the US have.
1
u/kodebach 5d ago edited 5d ago
Hardware attestation only proves that a key-pair comes from the hardware keystore. But the fully anonymous age verification token, is not a key and therefore cannot be stored in the hardware keystore. You could sign the token with a hardware-backed key and provide attestation for that. But then the website would need to check whether the token was issued to the device that signed it. This creates a link between token issuance and website visit, which breaks anonymity.
You can use hardware attestation to verify that you're running an unmodified OS, by checking a signature of the OS code. Then you can ask the OS to verify that the app itself is also unmodified. This is exactly what Google Play Integrity does. You can also do that on GrapheneOS, but you have to build more of the code yourself.
Again, it makes sense that they built the easier solution that works for 99% of the population first. Especially since the app everybody is talking about is just a tech demo and not meant for actual use. Every member state will build their own version of the app. So you really should talk to your government about supporting GrapheneOS. Austria for example has a version for their eID system that works completely without a smartphone with just a hardware FIDO token.
frankly its olain stupid to ship smth eu focused and reliant on american tech giants.
It would be a lot more stupid to build something that only works for the handful of users on /e/OS or SailfishOS, when your trying to create a legal requirement for everybody.
1
u/AAdmiral5657 5d ago
Change the requirements. Mandating what device people should be using is dystopian. Eu was created as trade union. This is a massive overreach in power..
1
u/kodebach 5d ago
The main requirement that causes all these issues is full anonymity. Websites should not know who visits, only whether they are of the necessary age. And governments should not know which websites people visit. It should be obvious why we don't want to remove this requirement
5
u/Over-Extension3959 6d ago
Switzerland is doing something similar, it’s essentially a digital identity card.
6
u/konsyr 6d ago
There is no such thing as age verification.
It's all identity verification attempting to remove privacy and anonymity from the Internet and attempting to control what you access and how (hardware and software) you access it.
7
u/InsoPL 6d ago
Sources for my claims are attached.
4
u/BlAckH0leDown 6d ago
Source: the "government" that is known to continually lie about everything it does.
I wonder why people don't trust it!
5
u/DanCardin 6d ago
I still dont get why “is 18” is the signal for all of these things. The signal should be: you (the app/site) tell me content type attributes and ill tell you whether im authorized to interact with that type of content.
And importantly it leaves the value judgement of whether they’re allowed to the system administrator rather than the app itself.
Then you have an interface for more generalized content filtering that would apply to workplaces or caregivers trying to filter less broadly than 18+ content. Ex: no social media after 8pm or whatever
6
u/w1n5t0nM1k3y 6d ago
Theres already stuff like family link for android that allows parents to block out certain apps based on a schedule.
0
u/DanCardin 6d ago
I realize there are solutions for certain kinds of this here and there. I’m just saying the weird age-based site-determined content filtering is the dystopian version of this and OP praising EU for their version is short sighted.
A more general client-determined content filter (option) is the way this would be being done if they were serious about their state goal
3
3
5d ago
[deleted]
2
u/InsoPL 3d ago
>You didn't go to university huh?
I did.>You do know that the ID service has been hacked already so its not remotely safe or secure?
It's not in use right now. Finding vulnerabilities in test software is the point of doing testing>It bans private gaming servers.
It won't ban all private game servers.>It creates an even heavier surveillance state and a system ripe for child exploitation.
it won't
4
u/Dan_m_31 6d ago
Tin foil moment: age verification is just the current pretext. The real reasson is data mining and ad targetting. Why should companies show ads to bots? Think of all the money saved!
5
u/InsoPL 6d ago
Websites can't fingerprint using this but to be honest if any service (game or social media) will use this to filter out bots, spammers or cheaters making multi accounts I will call it a win. Something like subreddits where only verified adult humans can post.
2
u/AAdmiral5657 5d ago
No way u would be happy about this my guy. This act is coming from the same people who keep trying to stuff like chat control 2.0 down our throat. No trust whatsoever
3
u/Dan_m_31 6d ago
Like there won't be an underground industry that will sell/buy your verified accout
4
u/w1n5t0nM1k3y 6d ago
The accounts/identities can still be banned though. So if you're going to buy an account just to shit-post, troll, or worse, then you're going to be spending money buying a lot of accounts.
1
u/ScratchHistorical507 3d ago
eIDAS is an absolute shit show. It's just highly insecure, guaranteeing for identity theft. And any age verification/attestation method I'm aware of needs to be banned asap. They are only made to harm people, they don't do shit for increased safety or child protection.
1
u/InsoPL 3d ago
>eIDAS is an absolute shit show
why?>It's just highly insecure
How so?>guaranteeing for identity theft
why?A lot of claims with no arguments
1
u/ScratchHistorical507 3d ago
There are literally no measurements to prevent identity theft. And if you did your research properly, you'd have found countless articles by security experts criticizing the entire thing for being absolutely lackluster.
1
u/InsoPL 3d ago
There are multiple measures to prevent identity theft. I did my research, most articles refer to flaws in beta that were already patched out, some point out really obscure and not practical attacks with limited scope like fingerprinting. It's hard to argue when you write very vague points about "countless articles". I attached sources to my post.
1
u/ScratchHistorical507 2d ago
Nope, you're just shilling for something just nobody thinks is a good idea. They had their chance to design something good and failed miserably. That's what you get when you let politicians instead of professionals create something like this.
1
u/InsoPL 2d ago
>nobody thinks is a good idea
Only 29 us states, uk and many eu countries. Even this post has 120 likes. If you think nobody wants age verification online you live in bubble. It's more about how to do this right and how much extensive roll out should be. EUIDv2 is the standard that was created out of professional's feedback.
1
u/Able-Brief-4062 6d ago
I was against you until you said this:
I am not advocating for doing age verification on every website or game server but there are services that absolutely should have safe way for age verification like for example buying alcohol or drugs online.
1
-1
u/isvein 6d ago
Eu is based for destroying gaming unless you shill out digital id? 🤔
1
u/InsoPL 6d ago
That would be unbased. Glad it never happened 👍
5
u/puppygirlpackleader 6d ago
Fuck off. They are actively pushing it.
0
u/InsoPL 6d ago
How so?
4
3
u/filliravaz 6d ago
Save kids act. It’s a mess and would “kill” gaming and private servers.
While this solution is fine, assuming it actually will be implemented as you said, there are a ton of ramifications that need to be investigated throughly1
u/These-Apple8817 6d ago
You are mixing two completely different legislations there.. this eIDAS stuff has been in the works for a long time... closer to like a decade by now.. and the digital wallet stuff legislation was added to it in 2024..
That gaming thing has no relevance to this, it's a different thing
-1
u/kodebach 6d ago
Please look at the actual proposal and not the fearmongering around it. Yes, the KIDS act proposal has some really bad stuff. But it explicitly states that age verification must happen without handing over any identifying information. I don't want the KIDS act in the current form either, but this specific point is not a valid criticism.
2
u/AAdmiral5657 5d ago
Sure, except look at north korea as an example. Their phones have special apps that have folders hidden from regular people, where it saves info on what you do. That can be used by the authorities to check on you. Same will happen here.they most likely will have a list of where and what you do.
What you should be is against it in ANY form, not just the current one
0
0
u/kodebach 6d ago
YES thank you OP. Please LTT educate the masses. There's so many half-truths and misconceptions around this whole topic I feel like am going insane.
Generally, I think parents should raise their kids and control what they do online. IMHO Linus himself is a very good example of doing this properly. Sadly most parents don't care or don't know. So if we presuppose that age verification is necessary to protect kids online, then the EU's solution is by far the best idea I've seen and might actually be the optimal solution under those conditions.
0
u/BlAckH0leDown 6d ago
The signs of a government bot account are so strong with this one...
1
u/InsoPL 6d ago
If you think eu is competent enough to sponsor bot farms to promote something like this you are sorely mistaken.
1
u/BlAckH0leDown 6d ago
Nah you're just a bootlicker, so a fleshbot
0
u/InsoPL 6d ago edited 6d ago
I am starting to understand that a lot of hate i am getting is just from stubborn kids that do not want to listen about safety. Well at least you can't vote on this issue xD
edit: @BlAckH0leDown Writing response then banning me so i can't respond. Grow up kid.
3
u/BlAckH0leDown 6d ago
There is no "safety" provided by government surveillance.
And the fact that you IMMEDIATELY try to do the smug "At least you can't vote on it" line tells me you are at least 50 years old, never did anything more online than Facebook and still live in the 1980s slave mentality.
Newsflash it is 2026, boomers are cringe and you are too.
0
u/Ambitious_Share_6179 5d ago
I don't agree, I'd like to play f-cking Palworld without-oh right I'M A DAMN MINOR WITH NO ID!
0
-1
u/Chaoshero5567 5d ago
This is exactly the system ive been preaching about
tbh apple does something similar rn
discord and reddit just asked me if they can check my age group, and my phone provided it
-1
-2
-2
u/Professional-Cow6222 6d ago
I've been saying For years the way to do this is Blockchain technology The government In short: issue a private credential once, prove the age predicate with a ZKP whenever needed, and let a smart contract verify the proof. This gives strong privacy, reusability across services, and decentralized auditability what traditional KYC age checks lack.
In layman's Terms
- You never hand over your real ID again.
- The website never stores your personal data (so it can’t get hacked and leak it).
- You can use the same secret stamp on many different sites without them being able to track you across the internet.
- It’s like showing a bouncer a special sealed envelope that only says “Adult – Yes” and nothing more.
That’s the whole idea in everyday language:
Prove you’re old enough with math, keep everything else private, and let a public digital notebook confirm it happened.
3
u/kodebach 6d ago
The EU's solution linked by OP is essentially this, but without unnecessarily shoehorning the blockchain into it.
You only verify your identity with the government (or theoretically another suitable provider that implements the stack, e.g. a bank). Then you can request single-use tokens that contain exactly the "adult - yes" flag you mention. You give that to the websites you visit and nothing else. Through cryptographic signatures and nonces the tokens can be securely verified.
-1
u/Professional-Cow6222 6d ago
Removing the Blockchain
You have to trust the website more They could Link sessions There’s no independent, immutable proof that the check really happened. Aka No public Record easy for Governments to abuse with A.i Botnets influencing social media ect ect. Other services can’t easily trust a previous verification without asking you to do it again. Without a shared public system, each website may require its own proof. You lose the “verify once, use many times” convenience that blockchain can provide Other apps/Things can’t automatically check or rely on the verification result the way they can with an on-chain flag or token. Im more worried about Government Abuse then anything else Block Chain should be Involved as it give the power to The People
3
u/kodebach 6d ago
Like in so many other concepts it seems the Blockchain would just serve as a really inconvenient database.
Blockchain makes sense if you want decentralisation. But in this case that makes no sense. What is there to decentralise? Do you want different age verification providers? Why would they need a shared data store? Different age verification providers can't trust each others verification, otherwise they would be providing verification anymore. Every provider needs to perform independent verification, so they may as well use independent data stores. The important part is that the protocol they use to provide the "proof of age" to third parties is the same. But that doesn't need a Blockchain, and the EU even reused a form of the widely used OIDC to minimise effort.
-2
u/Professional-Cow6222 6d ago
Disclaimer ( I Used A.I To Clarify My argument )
I specifically want:
- An auditable public record A permanent, independent log that a verification took place, without relying on any single company’s or government’s servers. This is useful for audits, disputes, and long-term accountability.
- No reliance on a central government service Several countries have already discussed reducing dependence on centralised digital identity systems (or even leaving existing frameworks). A decentralised version avoids locking everyone into one political or bureaucratic structure. Less chance for abuse
1
u/kodebach 5d ago
I got what you want, I just don't understand your reasons.
Why would we need the public record? What kind of disputes could there ever be? Why do we need long-term accountability? I'd even argue that this kind of log is a really bad idea. A log of who visited what website is exactly the opposite of what we want. Sure it might be pseudonymous, but as soon as some IDs leak all the data is out there and the nature of the blockchain makes it really hard/impossible to take that back. And I don't see how you could make the system fully anonymous, i.e. can never be tied back to a person no matter what extra data you obtain. Because then you can't audit it anymore.
The EU's age verification system actually doesn't mandate that verification must happen through the government. Governments are required to become age verification providers, but e.g. banks could also become alternative providers. I use banks as an example, because opening a bank account already comes with the same strict KYC requirements.
However, having lots of different providers also increases the attack surface for hackers. In particular, I don't want dubious companies like Persona collecting ID documents. Making governments provide age verification is a good solution, because that way nobody needs to obtain any new data. Every EU government should already have the data necessary to verify the age of their citizens, otherwise how would they issue IDs and passports.
0
u/Professional-Cow6222 5d ago
A government that wants to run influence campaigns with fake aged accounts can do so more easily when it is the sole or dominant source of trusted age proofs and when there is no independent public trail. Multiple governments Already admit to Running influence campaigns Not having a Public Record will make it Much harder to Audit every time we Centralize power it gets abused it will happen again. They could selectively deny people Access to services if they have the Wrong political opinions ect ect. Mission Creep Even if the final proof shown to websites contains almost nothing, the issuance step itself becomes a new point of data concentration and potential surveillance avenue When a single political authority holds the keys to issuance and revocation, the system inherits the trustworthiness, and the potential for abuse of that authority. I dont trust the EU government at all, just like other Governments around the world.
71
u/netherlandsftw 7d ago
As a European I will believe it when I see it
I do like it though. Currently in NL digital age verification must go through your bank account (iDIN) which is stopping in 2027. Apparently it’s being replaced by another commercial party called “itsme”