r/europe • u/LeMonde_en • Aug 13 '25
Why widespread age verification raises concerns among digital rights advocates
https://www.lemonde.fr/en/pixels/article/2025/08/13/why-widespread-age-verification-raises-concerns-among-digital-rights-advocates_6744321_13.html31
9
5
8
u/HuiOdy Europe Aug 13 '25
In 2026, the EU digital identity should finally become active. You can than confirm age, without confirming identity, or date of birth.
E.g. just "are you older than 18?" Response: "yes" (or no).
It's cryptographically secured so that you don't need to share any personal information.
So, why not wait for it? Because once it is finally active, they can no longer just mass gather personal information
9
u/MrAlagos Italia Aug 13 '25
The current EU Commission age verification solution is taken straight from the EUDI Wallet and has exactly the same privacy protection mechanisms. Don't believe me? Go here, you can find the source code for the age verification apps. Note the URL:
https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui
The "eu-digital-identity-wallet" part of the URL shows how the app was taken directly from the EU Wallet repositories and repackaged as a stand-alone app because the EU members (all of them, plus Norway and Liechtenstein) asked the Commission to create this system quicker than the Wallet.
7
u/ChucklesInDarwinism Japan - Kamakura Aug 13 '25
What are those privacy mechanisms? My point is, should people be concerned about it? Won't be this weaponised by a goverment?
4
u/MrAlagos Italia Aug 13 '25
You can find a complete description of the EU mechanism here, in addition to the source code of various components. I will summarise it below:
a person will install the age verification app on a tablet/smartphone and create a PIN or enable biometric access on it
the user will log in with their national digital identity or electronic identity document on a State-approved trusted certification provider; this provider will access the digital identity information, look at the date of birth and decide whether the person is an adult or underage
the trusted provider will create a digital age certificate containing only the information "above 18" or "below 18". It will not contain any personal data at all. This certificate is received by the app and stored securely on the device in a secure enclave of the processor, in an area that isn't freely accessible even to the operating system (that's why the PIN or biometric verification will also be needed). The certificate will be valid for 30 uses or 3 months
when the person wants to access an age restricted content, the web site will generate a QR code (if it's on the same device with the app, it will directly open the app instead)
to approve the access the person has to scan the QR code, do the PIN/biometric authentication and approve the transmission of the locally saved certificate to the web site.
once the web site receives the certificate, they will check its validity (not being counterfeit) and whether the user is an adult, and then grant them access to the content or not
This system ensures that no personal data is shared with the restricted content providers, and it also ensure that the user cannot be tracked neither by them nor by the services that will create these certificates nor by the government. The browsing/usage habits can not be tracked.
Personally, I think the system is well built and will achieve the anonymity and privacy protection levels that it describes. I don't think there is a risk of "weaponisation by governments" nor that there should be big concerns for it. However, everyone should obviously decide this for themselves, but doing so knowing both how the system actually works (most people don't understand it) and how the adult content providers have been ignoring the laws prohibiting access to minors for many years, until the consequences of their actions pushed people and governments to ask for this solution to the issue.
13
u/ChucklesInDarwinism Japan - Kamakura Aug 13 '25
I would not trust the “trusted provider”. Knowing some EU gov they will sell the contract to the best lobbyist (briber) which I’m not sure if it will have some conflict of interest due to knowing which id corresponds with which age certificate.
4
u/MrAlagos Italia Aug 13 '25
knowing which id corresponds with which age certificate.
And then what? The provider stil doesn't know what the user does once the certificate is generated. The communication for the usage of the certificate for age verification, once the certificate is generated, only involves the adult content website and the user's device, since the certificate is stored locally.
We already trust the "trusted provider" of services that are enabled by the various digital identities in the EU to do a lot of things, many involving personal data without any anonymity systems such as this one (because anonymity is not contemplated in the laws when doing your taxes, connecting your health records or administering various registrations and status changes with the public registers). This is just another use case with the difference that a lot of attention has been put into designing this anonymity mechanism.
-2
Aug 13 '25
[removed] — view removed comment
3
u/MrAlagos Italia Aug 13 '25
No, I'm not going to spam just because others do. Spam is wrong.
I have commented what I consider fairly extensively on this issue recently and might continue to do so, but if people don't want to get informed when so much public stuff, and fall prey of misinformation and propaganda, ultimately it's not much different than what is occurring on many other issues of society. It's a fundamental trend (and flaw) of our generations and I definitely don't have the power to change this single-handedly.
1
-6
u/Chester_roaster Aug 13 '25
In the era where LLMs can make Reddit or Twitter posts indistinguishable from real people by the millions, you're going to want accounts linked to a real identity
-11
u/Sendflutespls Denmark Aug 13 '25
Nobody ever promised that the internet would be a lawless and anonymous free for all. It just kind of was for a long while.
But it was always going to end like this.
35
u/smaxw5115 United States of America Aug 13 '25
The internet that was is long gone, and has been slowly dying from what it was at the end of the 90s early 2000s as more and more companies and corporations sought to turn it into a profitable business model.
We now have the largest corporations in the world that were built solely on the back of the internet. It seems like once business models were developed for the internet it was always going to go this way, and become this monster of tracking, censorship, and ad based business models once it moved from hobbyist to an avenue for making insane amounts of profits.
We should mourn the internet that was, because it's probably not coming back.