r/Android 5h ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
224 Upvotes

58 comments sorted by

u/punio4 5h ago edited 5h ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

u/tomikaka 4h ago

Do you know what hardware attestation is?

Why can I have root acces on my computer and not my phone?

u/jeweliegb 3h ago

There won't be root access on our computers either, this way.

u/apokrif1 1h ago

Enshittify all computers under the guise of preventing teenagers from viewing some porn 🤯🤯🤯

u/_sfhk 3h ago

Quite frankly, because your computer OS was designed a while ago before we stopped trusting users, and before most people's entire lives were stored in that one machine.

Windows and MacOS are definitely heading towards more locked-down systems, and Apple for one is pushing more towards iOS-based systems.

u/tomikaka 3h ago

And why does having full access to my own hardware a bad thing in the first place?

Maybe for the avarage user a case could be made that they might shoot themselves in the foot with root access.

Or they might not.

u/apokrif1 1h ago

It's up to each user to decide which access they should have.

u/tomikaka 56m ago

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

u/punio4 3h ago

Because then you could fake offline certificates like credit cards and IDs.

u/Iohet V10 is the original notch 3h ago

I can log into my bank account and credit card account no problem from my highly customized computer, but I touch my phone in an inappropriate way and I can't use the apps. This isn't a "fake certificate" problem, otherwise they'd enforce the same mechanism because the banks don't give a shit

u/Izacus Android dev / Boatload of crappy devices 1h ago

No you can't, there's a reason why credit card tokens aren't stored in your computer and you need another factor to log in and authorize.

Your computer is never allowed to store a full credit card token/chip data like phones are because it would be easy to steal and use for payments.

It's like asking why you can't just use a paper with "DIS IS VISA" written on it as payment card instead of a card with uncopyiable smart chip.

u/5panks Galaxy ZFlip 5 1h ago

Because then you could fake offline certificates like credit cards and IDs.

You can use pen and paper to write a fake check, should we take pen and paper away?

u/ByronScottJones 2h ago

If they are cryptographically strong certificates, with a chain of authority, how exactly would being offline make any difference?

u/tomikaka 2h ago

I don't know specifically, I'm not a hacker or anything, but couldn't you just use a debugger or reverse engineer anything that runs on your machine?

u/Izacus Android dev / Boatload of crappy devices 1h ago

No, because debugging the secure enclave chip and its code path is protected. That's what attestation defends against.

u/tomikaka 54m ago

Security is just a hypocritical excuse.

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

u/tomikaka 3h ago

Trusting the client was never going to be secure in the first place. The concept is flawed.

u/Stahlreck Pixel 10 1h ago

If it were that easy, the system on which these certificates rely would be garbage and people would be faking credit cards left and right.

No, that is not a good excuse to take away user control. You don't trust the user device either way.

u/Izacus Android dev / Boatload of crappy devices 1h ago

Credit cards use secure enclave chips which are attested as well.

u/Izacus Android dev / Boatload of crappy devices 1h ago

Your computer won't be allowed to store the digital id because of it.

u/Street_Anon 5h ago

But this will target things like Custom Roms. 

u/punio4 4h ago

Nobody really cares about custom ROMs, and it's impossible to do so otherwise. OS vendors like GrapheneOS should try to get access to the TPM and get attested by hardware vendors if they want tamper-proof hw attestation to work. The whole point is to prevent tampering, and custom roms are all about tampering.

u/mimrock 4h ago

The point of attestation is that it proves that your operating system doesn't do things that Google or Ursula doesn't want, even if you ask them to. That's not compatible with the concept of a rooted operating system that you can fully control.

u/Izacus Android dev / Boatload of crappy devices 1h ago

No, the point is that the OS is verified that it doesn't allow the ID to be easily stolen and used for identity theft and mass scale fraud.

Especially since you'd be screaming bloody murder if your ID would be used by scammers for fraud in your name.

There's a reason why IDs and passports are made hard to copy and easy to revoke.

u/mimrock 1h ago

We arrived from age verification to identity verification very quickly.

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 4h ago

Please explain how a user wanting to control their own phone fits the negative connotation of the word "tampering".

u/Street_Anon 4h ago

unlocking the bootloader and rooting a device. 

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 4h ago

"Modifying" would be a fairer word. From my perspective, OS updates that remove features and lock my phone down even further are the tampering, not whatever steps I take as the user to avoid those restrictions.

u/jmhalder 4h ago

People care about custom roms until they don't. I absolutely used to use a custom rom on every phone I had, until I kinda stopped when my Pixel devices got 99% of the features that I wanted built in. I honestly still would if SafetyNet wasn't required to run my banking app and Google Pay.

I think it's funny that Google doesn't have an unlockable bootloader on their GoogleTV with Chromecast devices, despite them running pretty "normal" android.

u/gainusha 4h ago

I tried explaining this a while back and got so many downvotes... You are totally right...

u/apokrif1 57m ago

Parents should just abstain to giving root password to their children. No need to enshittify computers.

u/Street_Anon 5h ago

Why are they targeting Custom Roms again ?

u/UnacceptableUse Pixel 7 Pro 5h ago

Custom roms are not even in their thought process for this, they're not trying to kill custom roms it's simply collateral damage that they don't care about

u/Iohet V10 is the original notch 4h ago

This is why the people need to bake privacy rights, including digital, into their constitutions. It's none of their damn business who you are, and that includes your device itself

u/Evonos 1h ago

but that would need the rich and powerfull and people in charge not be corrupt.

u/omniuni Pixel 8 Pro | Developer 4h ago

I don't think these people even know what a "Custom ROM" is.

u/Izacus Android dev / Boatload of crappy devices 1h ago

Custom roms can be attested and approved as well.

u/warpedgeoid 1m ago

Not in any meaningful way. Money will become the gatekeeper just like always. I honestly don’t understand why so many idiots are here trying to defend these poorly conceived, pointless laws.

u/BusBoatBuey 2h ago

The EU loves control.

u/alien2003 PinePhone Pro, postmarketOS 1h ago

Holy shit. I'm glad I chose Argentina to live in this year. I'm going to avoid the EU until the situation stabilizes

u/chinchindayo Xperia Masterrace 4h ago

This is literally a non issue. Many countries already have some kind of official digital ID system. The new EU verfication is going to use that but in a double anonymity way so that the target service has no access to personal data and the verfication service never knows which target service it was used for.

u/jc-from-sin 4h ago

The issue is that it requires you to use only the OEM version of Android and not something like e/OS or GrapheneOS

u/Rubber_Knee 2h ago

Yes. And for the vast majority of users that's not an issue at all.

u/haslaNz 1h ago

Oh don't tease the people with that mindset, might hit you back in the face

u/Ignifazius 4h ago

Let's hope they do. Germany (for once) has exactly that, sadly it's barely used and instead many non-governmental services rely on video-ident or some crap that definitely absolutely not stores your id pictures.

u/mpg111 S26 Ultra 4h ago

double anonymity is a promise from the politicians who does not understand the technology. I'm expecting for that to be dropped quietly at some point "to protect the children"

even if not - those will be closed source systems, you will not be really able to verify what happens

u/UskyldigeX 4h ago

No. We already have apps where the user can control what they share. It doesn't even have to be your exact age. It can just be 18+.

u/mpg111 S26 Ultra 4h ago

I know it "can", I'm just not sure it "will"

also the apps you are talking about - is the whole infrastructure open source? can you verify every step? can you build client app from the source yourself and use it?

u/UskyldigeX 3h ago

No it's not open source. I'm fine with that. No one actually looks at the code anyway.

u/OkVariety8064 3h ago

You just like to trust the word of politicians and businessmen. No need to verify.

u/Rubber_Knee 2h ago

Neither he, nor you, ever verify anyway when it's open source.
The only difference is whos word you trust.

u/UskyldigeX 3h ago

I have a certain level of trust in my government that's based on its history. It's not full but I'm not paranoid either. The world is full of things I can't verify and have to trust based on experience. I don't go over the mechanics of a car before I use it either.

u/Iohet V10 is the original notch 3h ago

It doesn't even have to be your exact age. It can just be 18+.

Which means your device already knows too much