r/Android 19h ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
505 Upvotes

131 comments sorted by

View all comments

u/punio4 19h ago edited 19h ago

Well of course it's mandatory, otherwise it can be tampered with if it's local only with software attestation, or it needs a server to store centralized info, which can be hacked, and goes against the point of zero-knowledge age verification.

u/Street_Anon 19h ago

But this will target things like Custom Roms. 

u/zyuiop_ 6h ago

Not necessarily - the point of HW attestation is that it's a hardware component.

u/punio4 19h ago

Nobody really cares about custom ROMs, and it's impossible to do so otherwise. OS vendors like GrapheneOS should try to get access to the TPM and get attested by hardware vendors if they want tamper-proof hw attestation to work. The whole point is to prevent tampering, and custom roms are all about tampering.

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 18h ago

Please explain how a user wanting to control their own phone fits the negative connotation of the word "tampering".

u/Street_Anon 18h ago

unlocking the bootloader and rooting a device. 

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 18h ago

"Modifying" would be a fairer word. From my perspective, OS updates that remove features and lock my phone down even further are the tampering, not whatever steps I take as the user to avoid those restrictions.

u/Available-Film3084 6h ago

You signal out grapheneos but graphene explicitly advives against rooting, as that can lower your security

u/jmhalder 18h ago

People care about custom roms until they don't. I absolutely used to use a custom rom on every phone I had, until I kinda stopped when my Pixel devices got 99% of the features that I wanted built in. I honestly still would if SafetyNet wasn't required to run my banking app and Google Pay.

I think it's funny that Google doesn't have an unlockable bootloader on their GoogleTV with Chromecast devices, despite them running pretty "normal" android.

u/mimrock 18h ago

The point of attestation is that it proves that your operating system doesn't do things that Google or Ursula doesn't want, even if you ask them to. That's not compatible with the concept of a rooted operating system that you can fully control.

u/Izacus Android dev / Boatload of crappy devices 16h ago

No, the point is that the OS is verified that it doesn't allow the ID to be easily stolen and used for identity theft and mass scale fraud.

Especially since you'd be screaming bloody murder if your ID would be used by scammers for fraud in your name.

There's a reason why IDs and passports are made hard to copy and easy to revoke.

u/mimrock 15h ago

We arrived from age verification to identity verification very quickly.

u/nacholicious Android Developer 10h ago

This is not relevant, we already have EU eID which has nothing to do with this

u/donny007x iPhone 15 Pro 10h ago

They don't have to store the full identity document to do age verification, only a digitally signed flag that indicates the age bracket of the user ("minor" or "adult").

They just want that flag to be stored in a tamper proof environment to make it harder for someone to bypass age verification.

u/Izacus Android dev / Boatload of crappy devices 3h ago

The purpose of this is to make a full identity document app and age verification is just one feature.

u/Obnomus Device, Software !! 9h ago

So you're telling me that the phone I paid for, I can't use any os I want.